Data Recovery Case File · Trust, Practice & Honest Limits · A New Key Does Not Open the Old Lock
FileVault Enabled and the Recovery Key Is Gone
His enquiry described a distressing situation and contained one technical misunderstanding worth correcting immediately, because it is the thing standing between him and a realistic plan. He has lost access to his Mac: his password no longer works, fingerprint sign-in is unavailable, and after discussions with support he was told that disk encryption has been enabled on the machine. Then: "my original recovery key is not accessible at the moment. But when I generated a new recovery key it is too big." That last sentence is where the misunderstanding sits, and it matters more than its length suggests: generating a new recovery key does not produce a key that opens the existing encryption. This page sets out the honest technical position, what to do first — which is not about the data at all — and where the original key may still exist.
| Media | Mac with full-disk encryption enabled — account password no longer accepted, biometric sign-in unavailable, original recovery key not to hand |
| Reported situation | Access lost to the machine · encryption confirmed as enabled following discussion with support · original recovery key not currently accessible · a newly generated key found not to work |
| Fault class | No device fault — credentials case; data reachable only with the password or the original recovery key, and honestly unreachable without either |
| Equipment used | No bypass attempted or offered · account security guidance issued first · original key locations identified and worked through · decryption only ever against lawfully-held credentials (Passware Kit Forensic) · limits stated in writing |
The decode: why a new key does not help, what to secure first, and where the old key lives
Why generating a new key changes nothing: full-disk encryption protects the volume with a key established when protection was switched on. A recovery key is a way of releasing that existing key — it is a spare route to the same lock. When a system offers to generate a new recovery key, it can only do so from a session that is already authorised, and the new key becomes a route to the same volume going forward. It cannot be created from outside and it cannot retroactively open a volume you are locked out of. So a key generated now, of whatever length, is not a key to the data he cannot reach. That is why it did not work, and it is worth understanding clearly rather than continuing to try variations.
What to secure first — and it is not the data: the most useful advice on this page has nothing to do with recovery. If encryption was enabled on his machine without his knowledge and his password no longer works, the priority is the account, not the disk. That means going through the manufacturer's own account recovery process from a different device, changing the account password, reviewing which devices are signed in and removing any he does not recognise, and checking the contact details and recovery options on the account for anything that has been altered. A machine can be replaced; an account with access to mail, photographs, backups and payment details is the thing that keeps compounding. That comes first, today, before any question about the drive.
Where the original key may still exist: the realistic avenue, and worth working through carefully. Depending on how protection was set up, the recovery key may have been stored with the manufacturer's account — retrievable through their own account-based process — or displayed at setup with an instruction to print or write it down, in which case it may be among his papers or saved as a file or photograph on another device. Where a machine was ever managed by an employer or institution, their IT will hold it. Those are the places to look, and finding it turns an impossible situation into an ordinary one.
The honest limit, stated plainly: if the password is unknown and no original recovery key exists anywhere, then the data on that volume is not reachable — not by this bench, not by any bench, and not for any sum. Full-disk encryption without a legitimate key is not a lock to be picked; it is mathematics. This archive's position does not vary with the sympathy of the circumstances: legitimately-held keys only, and where none exists, the limit is stated rather than sold around. Anyone offering to bypass it is describing something that does not exist, and the offer itself is the warning.
On the bench
Nothing was attempted on the machine before the account guidance was given, because the sequence matters more than the technique here — securing an account that may have been accessed is more urgent than any question about a disk. The key locations were then worked through with him systematically: the manufacturer's account-based retrieval, printed or saved copies, other devices, and any institutional escrow. Where a lawful key was produced, decryption ran against that key alone through Passware Kit Forensic and the volume was read normally. Where none could be found, that finding was issued in writing, free of charge, with no work proposed and nothing sold.
The outcome
The account secured first, the key locations exhausted, and the position stated in writing either way. Free assessment and honest limits at no cost; where a lawful key exists, one fixed written figure including VAT and no recovery, no fee. The decode, for anyone locked out of an encrypted machine: a newly generated recovery key cannot open a volume you are already locked out of, because it can only be created from an authorised session and applies going forward — so stop generating variations; if you suspect the account rather than the machine has been compromised, secure the account first, from another device, because that is the exposure that keeps growing; hunt the original key in the account's own recovery process, in printed or saved copies, and with any employer or institution that managed the device; and understand that without password or original key, the data is genuinely unreachable, and any firm claiming otherwise is telling you something important about itself.
Locked out of an encrypted computer
Deal with the account before the disk. If your password has stopped working and you suspect someone else has had access, use a different device to run the manufacturer's account recovery, change the password, review every signed-in device and remove anything you don't recognise, and check whether the recovery contact details on the account have been altered. That exposure keeps growing while a locked laptop simply sits there. On the encryption itself: generating a new recovery key will not open the existing one — a new key can only be created from a session that's already authorised and applies going forward, so trying more variations won't help. Hunt the original instead: the account's own recovery-key retrieval, anything printed or saved at setup, photographs of a setup screen on another device, and your employer's IT if the machine was ever managed. And be clear-eyed about the limit — without the password or the original key, no one can open it.
Secure the account first — then call Leeds Data Recovery on 0113 322 3083; key locations worked through free, lawful credentials only, and the limit stated plainly if there is one.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.