Call us — 0141 404 0294
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Solid State & Flash · Which of Two Things Happened

When a Recovery Returns Encrypted Fragments

Her enquiry described a loss and a second disappointment on top of it. A 1TB SanDisk SSD: "there was one large folder on it which has now been accidentally erased. It contained tonnes of important work. The IT technicians at my school have run some recovery software on it and say that they can only recover encrypted stuff which they can't open. I am absolutely gutted as it's all gone." That verdict deserves examining before it is accepted, because "encrypted stuff we can't open" describes two completely different situations — one of which has a real route out and one of which does not. Establishing which she has costs nothing, and it should happen before she concludes anything.

Media1TB SanDisk solid-state drive used in an institutional setting — a large working folder erased in error; recovery software run by internal IT returning content described as encrypted and unopenable
Reported situationFolder erased accidentally · recovery software run by school IT · recovered content reported as encrypted and inaccessible · encryption status of the drive not established · owner treating the data as lost
Fault classDeletion on TRIM-enabled storage with the recovered output's nature undetermined — genuine encryption and structural incompleteness requiring different responses
Equipment usedDrive use halted · imaged write-blocked (Atola TaskForce 2) · recovered output examined to distinguish ciphertext from incomplete files · encryption and key-escrow position established · decryption strictly against a lawfully-held key

The decode: two explanations, and which one to hope for

Explanation one — the drive really is encrypted. On a managed device, or on a machine with device encryption enabled at setup, everything written to the storage is encrypted at rest. Recovery software run against such a drive without the key recovers real data that reads as meaningless — which is precisely how a technician would describe it. This is the hopeful branch, because encrypted data is intact data behind a lock, and on a school-managed device the key is very likely escrowed: held centrally by the organisation's IT, exactly so devices can be recovered. The people who reported the problem may be the people holding the solution, and the question worth asking them is not "can you recover it" but "do we hold the recovery key for this device".

Explanation two — the files are simply incomplete. When recovery software cannot read a filing structure it falls back on scanning raw content, and where it cannot determine where files end it pads or truncates them. The output is structurally broken and opens as noise, which people commonly describe as encrypted because that is what it looks like. This branch has no key to find, and the honest position is poorer.

How to tell them apart: it is a straightforward examination rather than a guess. Genuinely encrypted volumes carry recognisable headers and structures, and the statistical character of ciphertext is distinguishable from that of truncated ordinary files. That determination is made on an image and it decides everything — including whether spending money makes sense at all.

The honest part about the SSD: said plainly because she should not be given false hope. A folder deleted from solid-state storage is subject to background housekeeping that clears freed blocks within minutes. If the deletion happened some time ago and the drive has been in use since, a good deal of it will be genuinely gone regardless of encryption. That makes speed the variable she controls: the drive should stop being used immediately, and it should not be scanned again.

What to ask her IT team today: whether the device is encrypted, and if so whether a recovery key is held. Those two questions cost nothing and determine which branch she is on.

On the bench

Use of the drive was halted first, since on solid-state storage every hour of ordinary use runs more housekeeping. The drive was imaged write-blocked on the Atola TaskForce 2, and the recovered output was examined to establish which of the two situations applied — encrypted volume structures and the statistical character of ciphertext being distinguishable from files truncated or padded by a scan. The encryption and key-escrow position was established alongside, since on a managed device the key is frequently held centrally. Where a lawfully-held key was supplied, decryption ran against that key alone and the contents were verified by opening.

The outcome

The two possibilities separated by examination, the key position established and the position reported before any expectation was set. Free assessment, one fixed written figure including VAT; where a chip has to be removed, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone told their recovery came back encrypted: that describes two different situations — a genuinely encrypted drive, where the data is intact behind a lock and the key may be escrowed with your organisation's IT, or files simply too incomplete to open, which look identical from outside and have no key to find; the difference is established by examination rather than guessed; ask your IT team whether the device is encrypted and whether a recovery key is held, because those two questions decide everything; and stop using the drive, because on solid-state storage the clock is running.

Recovery results described as encrypted

Ask two questions before accepting that it's all gone: is the drive encrypted, and does anyone hold a recovery key for it? On a work or school device the answer to both is often yes, because organisations enable encryption as standard and escrow the keys centrally so devices can be recovered — which means the people who told you the data was unreadable may be the people holding the way in. That's the hopeful version, where your files are intact behind a lock. The alternative is that recovery software produced files too incomplete to open, which look exactly the same from outside and have no key to find. Distinguishing them is an examination rather than a guess. Meanwhile, stop using the drive entirely: if it's solid-state, background housekeeping clears deleted blocks within minutes, so every hour of use costs you.

Told your recovered files are encrypted?
Find out which of two things happened — call Glasgow Data Recovery on 0141 404 0294; imaged write-blocked, output examined to separate ciphertext from incomplete files, key position established first.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0141 404 0294