PanicStation.org
us Technology & digital loss

What to do if…
your device suddenly asks for a disk-encryption recovery key after a restart

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Do not wipe, reinstall, or type the key into any website or link you were sent. First photograph the screen, then use only the built-in recovery prompt and the official Microsoft, Apple, or work/school IT route to find the matching recovery key.

Do not do these things

  • Do not factory-reset, reinstall the operating system, erase the disk, or choose a recovery option that says it will remove files unless you have accepted possible data loss.
  • Do not enter a BitLocker or FileVault recovery key into any website, QR-code page, email link, text link, or support chat.
  • Do not give the recovery key to anyone who contacted you first, even if they claim to be from support, IT, Microsoft, Apple, IC3, or law enforcement.
  • Do not keep restarting repeatedly to see if the screen disappears.
  • Do not change BIOS, UEFI, Secure Boot, TPM, startup security, or disk settings while panicked.
  • Do not guess random keys or passwords if the screen is asking for a specific recovery key.

What to do now

  1. Pause at the screen and document it.

    • Take a clear photo of the exact message.
    • For BitLocker, include the first 8 digits of the recovery key ID if shown.
    • Write down what happened just before this, such as a Windows update, BIOS or firmware update, repair, battery issue, hardware change, or school or work IT change.
  2. Check whether this looks like a built-in recovery prompt.

    • A normal BitLocker or FileVault recovery request is part of startup, sign-in, or recovery, not a browser page.
    • If you see a web address, QR code, payment request, chat box, remote-support offer, or demand to sign in through a link, stop using that route and treat it as suspicious.
    • Use a separate trusted phone, tablet, or computer to look up the official support page yourself.
  3. Identify the recovery system before looking for the key.

    • Windows usually says BitLocker, device encryption, recovery key, or recovery key ID.
    • A Mac may refer to FileVault, the startup disk, a recovery key, or password reset options.
    • A work or school device may still show Microsoft or Apple wording, but the key may be held by the organization.
  4. If it is Windows or BitLocker, look for the matching key.

    • On a separate trusted device, sign in to the Microsoft account used on that PC and look for the BitLocker recovery key that matches the key ID on the locked screen.
    • If the device was ever connected to a work or school account, contact that IT helpdesk and give them the key ID from the screen.
    • Check places where you may have saved the key when encryption was turned on, such as a printout, USB drive, password manager secure note, or saved recovery-key file.
    • Microsoft Support generally cannot retrieve, provide, or recreate a lost BitLocker recovery key.
  5. If it is a Mac or FileVault, use the FileVault route that matches your setup.

    • If you saved a FileVault recovery key, use the exact letters and numbers from your own stored copy.
    • Do not confuse a FileVault recovery key with an Apple Account recovery key; they are not the same thing.
    • On some setups, the FileVault recovery key may be visible in the Passwords app on a trusted iPhone or iPad signed in to the same Apple Account as the Mac.
    • If the Mac is managed by work or school, contact that IT helpdesk before erasing anything.
  6. If this happened after a BIOS, firmware, TPM, hardware, or security update, treat that as a plausible trigger.

    • BitLocker may ask for a recovery key when it cannot automatically unlock an encrypted drive after a security risk or hardware change.
    • That does not by itself prove the device was hacked.
    • Still use only the official account, saved-key, or IT routes.
  7. If you think a scam or compromise may be involved, reduce exposure without derailing key recovery.

    • Do not join unknown Wi-Fi networks or use any link shown in an unexpected message.
    • From a separate trusted device, secure your email account first if you believe someone else may have access to it.
    • After you regain access, update and run the built-in security scan or a reputable security tool before using sensitive accounts on that device.
  8. If money, threats, impersonation, or online fraud are involved, report through official channels.

    • IC3 is the FBI-run route for cyber-enabled crime and fraud reports.
    • IC3 also warns that scammers impersonate IC3, so navigate to the official site yourself instead of using a link sent by someone else.
    • If someone is in immediate danger, call 911 or local police.

What can wait

  • You do not need to decide right now whether to wipe the device, replace it, pay for data recovery, or buy new software.
  • You do not need to prove the exact cause before trying the official recovery-key routes.
  • You do not need to contact multiple agencies just because a recovery-key screen appeared.
  • You do not need to make long-term security changes until you have either regained access or confirmed the key cannot be found.

Important reassurance

A recovery-key screen can appear after ordinary security, firmware, hardware, or account changes. The safest first move is to slow down, preserve what is on the screen, and avoid any step that could erase the device or expose the recovery key.

Scope note

These are first steps only to stabilize the situation, protect the recovery key, and avoid irreversible data loss. Later decisions about device repair, deeper security review, backups, or business incident response may need qualified IT or security help.

Important note

This is general information, not legal, forensic, cybersecurity, financial, or other professional advice. For a managed work or school device, follow your organization’s incident and IT support process.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us