There are two answers to this question and they are nowhere near each other. If you hold the login password or the personal recovery key, a FileVault-encrypted Mac is usually recoverable, including after the drive has physically failed. If you hold neither, the volume cannot be decrypted by us, by Apple, or by anyone advertising a bypass.
So the first job is not technical. It is to establish, before you spend a cent, which of those two situations you are in. Everything below is written to help you do that quickly, and to explain what is actually happening inside a Mac when FileVault is switched on.
Do this first, before anything else
Work through this list in order. Most FileVault cases are decided in the first hour, by what the owner does and does not do.
- Find the recovery key before you touch the hardware. It is the single thing that decides whether this is a recoverable job at all. Check your password manager, any printout or photo taken on the day FileVault was switched on, and, if the Mac belongs to your employer, ask their IT team.
- Stop guessing passwords. On a T2 or Apple silicon Mac the Secure Enclave deliberately slows each failed attempt, so repeated guessing achieves nothing except lost time. Write down every password you might plausibly have used instead, and try the most likely ones once each.
- If the Mac is dead, silent, or making a repeated clicking or grinding sound, leave it switched off. Every further power-up of a failing drive costs you readable sectors, and on an encrypted volume you cannot afford to lose them.
- Do not let anyone reinstall macOS or reset the machine. On a T2 or Apple silicon Mac a reinstall can replace the existing volume and its keys. “We will just reload the system for you” is how a great deal of recoverable data is lost.
- Ignore the erase prompt. When macOS cannot mount an encrypted volume it often offers to initialise or erase it. Decline, close the window and stop there.
- Note the basics. Model and year, macOS version, whether FileVault was switched on deliberately, and whether you hold the password, the recovery key, both or neither.
If the machine is physically failing rather than simply locked, that is a laboratory job. Our Mac data recovery diagnosis is free, and we will tell you at that stage whether the encryption puts the data out of reach.
What FileVault is actually doing to your data
FileVault is full-volume encryption built into macOS. When it is on, everything on the startup volume is stored as ciphertext: not only your documents, but file names, folder structure and the APFS metadata that describes where everything sits. Apple’s published description of the scheme is XTS-AES-128 encryption with a 256-bit key.
The important part is not the cipher, it is the key hierarchy. The volume is protected by a key that never appears in any form a human types. That key is wrapped by other keys: one derived from your login password, one derived from the personal recovery key, and on managed Macs one derived from an institutional key held by your organisation. Any one of those wrappers can unwrap the volume key. None of them can be worked around.
Two consequences follow, and between them they explain nearly every FileVault outcome we see:
- With a valid credential, the data behaves like ordinary data. Once unlocked, a FileVault volume is simply an APFS volume, and normal recovery technique applies to it.
- Without one, the volume is indistinguishable from random noise. There is no partial credit, no “we got most of it”, no reading the first few gigabytes to see what is there.
That is the honest shape of the answer. FileVault recovery is a question about credentials first and hardware second.
Where the recovery key actually lives
When FileVault is switched on, macOS generates a personal recovery key and displays it once. Most people click past that screen. It is worth spending several hours searching for it now, because it is worth nothing to you later.
- Your Apple Account, if you chose that option. The setup screen offers to let your Apple Account unlock the disk instead of you keeping a key. If you took it, signing in to that account is your route back in.
- A photo or screenshot. Search your photo library around the date the Mac was set up. A long alphanumeric string broken into short groups is what you are looking for.
- Your password manager or notes. Search for the words FileVault and recovery, and for any stray block of capitals and digits saved without a title.
- Your employer’s IT team. Company Macs enrolled in mobile device management usually escrow the recovery key automatically. Ask before assuming it is lost.
- Paper. Filed with the purchase receipt or the warranty card is more common than you would think.
If the Mac still starts and you can log in, do this today: confirm you have a current backup, then open the FileVault settings, switch it off and on again to generate a fresh recovery key, and store that key somewhere you will find it in three years.
Encrypted external drives and encrypted Time Machine backups have separate passwords of their own. Losing one locks that copy too, which is worth checking before you rely on it. The physical side of those cases is covered on our external hard drive recovery page.
When the hardware fails but you still have the password
This is the good case, and it is more common than people expect. A drive failing does not damage the encryption. If you hold a valid credential, the job becomes an ordinary media problem with one extra step at the end.
In the laboratory the sequence runs like this:
- Stabilise and image. We take a complete sector-level image of the encrypted container, working read-only from the original. For a spinning drive in an older Mac that can mean cleanroom head-stack work using donor parts we hold in stock. Where physical work is needed it is done only to make the media readable long enough to image it: you receive your recovered files, not a working device back.
- Unlock the image, never the original. The password or recovery key is applied to the copy, in a controlled environment.
- Rebuild and extract. The APFS structures are reconstructed and the files pulled out, then you receive the file list to confirm before anything is paid for.
Encryption does change one thing materially. On an unencrypted drive, a partial image is still worth something, because a technician can carve raw photos, documents and mail out of whatever sectors did read. On a FileVault volume there is nothing to carve until the container is unlocked, and unlocking depends on the encrypted metadata being intact. Completeness of the image matters far more, which is precisely why repeated do-it-yourself power-ups of a dying encrypted drive are so expensive in practice.
T2 and Apple silicon: the part people find hardest to hear
Every Mac with a T2 chip, which covers most 2018 to 2020 models, and every Apple silicon Mac from 2020 onwards encrypts its internal storage in hardware whether or not you ever switched FileVault on. The keys live inside the Secure Enclave on the logic board and never leave it. On those machines FileVault mainly adds the rule that your password must be entered before the Enclave will release the key at startup.
The consequence is blunt. The NAND flash chips and the logic board are a matched pair. Desoldering the storage chips and reading them on a programmer produces encrypted data with no key anywhere in it. If the Secure Enclave is destroyed, or the pairing between board and storage is broken, no laboratory anywhere can decrypt those chips. Not us, and not Apple.
What can sometimes be done is board-level work: restoring power delivery or a failed data path so the board comes back to life, starts up and accepts the owner’s own password. It is skilled work with no guarantee attached, and it is done for one purpose only, to make the storage readable so it can be imaged.
External and non-soldered drives are a far easier story, because an encrypted external volume is unlocked by a password you hold rather than by a chip fixed to one particular board. That is the usual position in SSD data recovery cases where the drive is not part of the Mac itself.
Why FileVault bypass offers are not credible
Search for FileVault recovery and you will find people advertising a bypass, an unlock, a crack. Consider what that claim would require.
- There is no known break of AES. A genuine method of decrypting XTS-AES without the key would be one of the most significant results in the history of cryptography. It would not surface as a classified advertisement next to phone screen replacements.
- Guessing is not bypassing. Against older, pre-T2 Macs it is technically possible to run a password attack against an image offline. That only works when the password was short or predictable, and it is a lottery rather than a service. On T2 and Apple silicon hardware even that route is closed, because attempts are rate-limited in the Enclave and the key never leaves it.
- Look at what actually gets delivered. The usual pattern is a fee taken up front, followed either by “no data found” or a machine handed back freshly wiped and reinstalled: working perfectly, and empty.
- Consider what you handed over. An encrypted copy of your entire working life, and quite often the password as well, given to an outfit whose central claim was already untrue.
None of this is a limitation of our laboratory. It is the entire point of the encryption. If a stranger could read a FileVault volume without your credential, FileVault would be worthless to you. The same reasoning applies on the Windows side, which is why our BitLocker recovery page says exactly the same thing: the owner’s own key, or nothing.
How an encrypted Mac is handled at our Singapore laboratory
We have been recovering data in Singapore for more than 20 years, with over 140,000 recoveries behind us and a 4.9 star rating from 909 Google reviews. On encrypted Macs the most useful thing we do is often the free diagnosis, because it establishes which of three situations you are genuinely in.
- You hold a credential and the media can be imaged. A normal job: quotable, and usually recoverable.
- The media is failing and the Mac is a T2 or Apple silicon model. The outcome depends entirely on whether the Secure Enclave and its pairing with the storage survived. We will tell you plainly what we find.
- You have neither password nor recovery key. There is no route, and we will say so rather than take your money.
The practical terms are the same as on every other case. Diagnosis is free. You receive a fixed written quote before any work begins. Nothing leaves our premises, because the work is done in our own in-house cleanroom at 6 Harper Road beside Tai Seng MRT. You see the recovered file list and confirm it before paying, and standard cases are no recovery, no fee. Everything is handled in line with Singapore’s PDPA, and an NDA is available on request. Where unlocking is required we will tell you before you commit, and you are welcome to be at the laboratory when the container is unlocked.
To start, bring the Mac or the drive to us, or send us the details and we will tell you what is worth doing. If you would like the shape of the numbers first, our data recovery cost page explains how quotes are put together.
