Call us — 0113 322 3083
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · A Password That Never Existed

External SSD Asking for a Password You Never Set

The enquiry described something that sounds impossible and has a mundane explanation. A 2TB Samsung T5 external SSD, used several times a week for a couple of years: "now it's throwing up that I need a password to unlock. Unlike another similar Samsung disk which asked me from the outset to install with a password, this disk never did, so I've never set up a password for it. But now I can't access my data. It's assuming I've a password." The comparison with the other drive is the useful detail — it establishes that the owner knows what enabling protection looks like, and that this drive never went through it. Which points at the likeliest answer: the drive is not protecting data behind a password so much as failing to remember that it has none. This page explains what that means, and — more urgently — the one action the manufacturer's own software will offer that would end the recovery permanently.

MediaSamsung T5 2TB portable SSD — in regular service for approximately two years; hardware security prompt now presented on connection; no password ever configured by the owner
Reported situationDrive suddenly requesting a password to unlock · owner confirms protection was never enabled, contrasting with a second drive that prompted at setup · data inaccessible
Fault classHardware security state fault — corrupted security configuration on a drive with encryption not knowingly enabled; controller-level assessment required, with genuine limits where protection proves active
Equipment usedController-level assessment of the security configuration state · vendor technological modes to establish whether protection is genuinely enabled or the configuration is corrupt · imaging on restored access · honest limits stated in writing where no lawful key exists; no vendor reset performed

The decode: what the prompt means, the honest fork, and the button not to press

How these drives handle security: portable SSDs of this class contain hardware encryption that is always present and can be enabled through the manufacturer's software. When it is switched on, the drive holds a security configuration recording that protection is active, and it demands a password before presenting any data. When it has never been switched on, that same configuration records that the drive is open, and the drive presents normally. The important consequence: the difference between a locked drive and an unlocked one is a small piece of stored configuration — and configuration can become corrupt.

Why the likeliest explanation is a fault rather than protection: the owner's evidence is good. A drive that had protection enabled would have required a password to be created at the moment of enabling — there is no way to switch it on invisibly — and the comparison with the other drive shows exactly what that process looks like. So a drive that never asked, and now asks, is most probably reporting a corrupted or misread security state: the configuration no longer says cleanly that the drive is open, and the controller defaults to the safe behaviour, which is to demand credentials. That is a fault to be assessed at controller level, not a wall.

The honest fork: stated plainly, because it must be. The alternative possibility is that protection genuinely was enabled at some point — by someone else with access to the drive, or during a software installation that was clicked through — and that a password really does exist somewhere. If that turns out to be the case and no lawful password can be produced, then the data is honestly unrecoverable. Hardware encryption on these devices is not a lock to be picked, and this archive does not claim otherwise. Which of the two applies is established by examining the drive's security state directly, and the answer is given in writing either way.

The button not to press: and this is the most valuable sentence on the page. The manufacturer's software, faced with a drive demanding a password nobody has, offers a way out: a factory reset or unlock procedure that clears the security configuration — and erases the drive in the process. It is presented as the fix, it is technically successful, and it destroys the data completely and irreversibly. Anyone in this position who follows the obvious path in the vendor's utility will end up with a working, empty drive and no recovery available at any price. Do not run it, do not let a shop run it, and do not accept any prompt that mentions resetting or unlocking the device.

On the bench

Nothing was run from the vendor's utility, on the principle that the manufacturer's remedy and the owner's interest point in opposite directions here. The drive was assessed at controller level, with its security configuration state read directly through vendor technological modes to establish the fork: whether protection was genuinely enabled and awaiting a real credential, or whether the configuration itself had become corrupt on a drive that had always been open. The finding was put in writing before any further step. Where the state proved recoverable, access was restored without any destructive reset and the drive was imaged completely and immediately, with the contents verified by opening and delivered on fresh media.

The outcome

The drive's security state established at controller level and the contents imaged and delivered, without any vendor reset being performed. Free assessment, one fixed written figure including VAT; where a drive has to be opened or a chip removed, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone whose drive suddenly wants a password: on these devices encryption is always present and must be deliberately enabled, which requires setting a password at the time — so a drive that never asked and now does is most likely reporting a corrupted security state rather than genuine protection; the honest alternative is that protection really was enabled and, without a lawful password, the data is beyond reach and will be described that way; and whatever you do, do not run the manufacturer's reset or unlock routine, because it clears the security configuration by erasing the drive.

Drive demanding a password you never created

Do not run the manufacturer's reset or unlock tool. On these drives that routine clears the security configuration by erasing the contents — it looks like the official fix, it works perfectly, and it ends any possibility of recovery. Don't let a repair shop run it either, and decline any prompt mentioning resetting or unlocking the device. Then think about what you know: enabling protection on this class of drive requires deliberately setting a password at the time, so if you were never asked to create one, the likeliest explanation is a corrupted security state rather than real protection — which is assessable at controller level. Be prepared for the honest alternative, though: if protection genuinely was enabled at some point and no lawful password exists, the data is unrecoverable, and you should expect to be told that rather than sold a maybe. Stop connecting it repeatedly meanwhile.

Drive asking for a password that never existed?
Don't run the reset — call Leeds Data Recovery on 0113 322 3083; security state read at controller level, findings in writing, imaged without any destructive unlock.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0113 322 3083