Data Recovery Case File · Study, Research & Family History · More Precious Now
The vault neither of them knowingly made: silent endpoint encryption decoded gently, the sealing dated from the stick's own records — and the photographs opened, and seen
Some enquiries state their stakes in three short sentences and need nothing added. "USB memory stick. Personal photos of myself and Wife. Wife passed away 10 months ago. These photos are more precious now." The obstacle: the stick "has been encrypted by ??" — his own punctuation — presenting a vault from an enterprise encryption product and asking, on any laptop, for "the password / key" that he does not possess and never set. His theory was the right one: "assuming either the company I worked for has set the encryption, or the company my wife worked for — although they are saying they have never used it." Could this be assisted with, and at what cost? Yes — and the decode below explains the mechanism that sealed the photographs without either of them ever being asked, why the denial from her employer was probably sincere and probably wrong, and the two honest roads to the password: the administrative one that worked, and the bench one held in reserve.
| Media | USB memory stick — a couple's personal photographs; the owner widowed ten months; contents sealed inside an enterprise encryption agent's vault |
| Reported situation | Password/key requested on every machine; never set by either owner · authorship uncertain between two former employers · one employer denying use of the product · assistance and cost asked plainly |
| Fault class | Orphaned corporate portable-media encryption — files intact inside a vault whose credentials live with an organisation, not a person |
| Equipment used | DeepSpar USB Stabilizer 10Gb write-blocked imaging of the corporate stick · Passware Kit Forensic container identification and key-based decryption against the image · verified delivery |
The decode: the silent seal, the sincere denial, and the stick's own testimony
How a stick gets vaulted without anyone deciding: corporate laptops commonly run endpoint-protection policies with a blunt standing order — any removable media inserted into this machine gets encrypted, automatically, before files can be written to it. No dialogue that registers as a decision; often just a moment's "preparing device" that nobody remembers. Plug a personal stick into a work machine once — to print something, to move a document — and it leaves wearing a corporate vault keyed to that organisation's system. Years later, on home machines, the vault finally introduces itself by asking for credentials that only an IT department ever held. Neither he nor his wife did anything unusual; they did the most ordinary thing in working life, once, near the wrong policy.
The denial, decoded without offence: her employer's "we have never used it" was probably offered honestly — and probably wrong, for a reason worth stating gently: front-line IT staff know products by their purchasing names, while a vault announces itself by an internal label that rarely matches. Denials in this genre are usually vocabulary failures, not evasions. Which is why the case turned to a better witness: the vault itself. Encryption agents write their bookkeeping onto the media they seal — product family, version, and, decisively here, when the vault was created. From the write-blocked image, that creation date was extracted and laid against the couple's employment timeline — and it fell squarely inside his tenure at his former company, on a product generation matching what such firms deployed in exactly that period. The question of authorship stopped being a dispute and became a date.
The two roads, ranked: the administrative road first, always: enterprise encryption systems are built with recovery in mind — administrators can release a vault or run a challenge-response unlock — and a former employer presented with the evidence, the owner's authority and a short goodwill letter usually helps, because the request costs them minutes. The bench road stands behind it: owner-authorised password recovery against his own property, with honest odds stated per product strength — some generations yield to methodical lawful work; the strongest do not, and this page would have said so plainly.
The recovery: released by the organisation the date identified
The stick was imaged before anything else — vault or no vault, the bytes were made safe first. The evidence letter went to his former employer's IT with the creation date, the product identification and his statement of ownership; their encryption console did in minutes what no amount of home guessing could — the vault released under their administrative recovery, applied to the image. And then the only verification this case could have accepted: the photographs opened and seen — the two of them, across the years the stick had quietly carried — checked through, present, whole.
On the bench
The stick was imaged behind the DeepSpar USB Stabilizer 10Gb — write-blocked as standard, since an encrypted volume deserves the same forensic caution as a failing one — and Passware Kit Forensic identified the corporate container type and its policy fingerprint, the detail that dated the vault and routed the case to the employer's IT. When the released key arrived, Passware applied it against the image, unlocking a decrypted copy while the original stick stayed exactly as her husband had left it. The bench's part was identification, custody and careful application; the authorisation was, rightly, the company's to give.
The outcome
The photographs delivered on new media, in duplicate at the bench's suggestion — more precious now, and now in more than one place — with a written account of the vault's origin story for his records. Free assessment, one fixed written figure including VAT, no recovery, no fee. His old employer's IT department earned this page's closing thanks: a few minutes of console work, and a decade of two people came home.
A stick asking for a password nobody in the house ever set
Suspect a work machine in its past — endpoint policies seal removable media silently, and the vault only speaks up on machines outside the company. Don't guess at the prompt endlessly, and don't reformat to "make it usable again": the files are intact inside the vault, and the vault keeps records — product, version, creation date — that identify which organisation can release it. Approach that organisation with evidence and ownership; sincere denials usually dissolve when the internal label is translated to the product name. And keep irreplaceable photographs off single sticks entirely — vault or no vault, one copy is one accident from none.
The vault's own records point the way — call Edinburgh Data Recovery on 0131 202 0491; opened under your authority, one written figure, no recovery, no fee.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.