Data Recovery Case File · Apple Mac · The Encryption That Stalled
A volume caught mid-encryption and abandoned: the terminal evidence read correctly, the known-bug diagnosis confirmed — and the data recovered by finishing, safely, the process the operating system left half-done
His enquiry was a piece of genuine detective work, and it deserves to be met as one. An older SSD from a Mac running a vintage macOS: "about three years ago it suddenly stopped working due to some corruption, and it caused a kernel panic. I have not used it since." His investigation: "I was checking the disk earlier and realised it cannot be mounted. I checked in the terminal, and found the system was attempting to encrypt the partition — but for some strange reason the encryption process had been stopped." And his research, unprompted and correct: "apparently it was a common issue with that macOS version." His question: repair the disk, or at least recover the data? The decode below confirms his findings — this is an interrupted disk-encryption, a known fault of that era's macOS, and emphatically not ransomware or any attack — explains why a half-finished encryption leaves a volume unmountable yet recoverable, and reaches the data by safely completing what the system abandoned three years ago.
| Media | Older SSD from a Mac (vintage macOS) — a partition caught partway through system disk-encryption; personal data aboard |
| Reported situation | Kernel panic and failure ~3 years ago; unused since · will not mount · terminal investigation shows an encryption process begun and then halted mid-way · owner correctly identifies a known OS-version bug |
| Fault class | Interrupted full-disk encryption — the volume left in a partially-transformed, unmountable state; data intact and recoverable with the correct keys/credentials and careful completion |
| Equipment used | Atola TaskForce 2 write-blocked imaging of the half-converted volume · Passware Kit Forensic FileVault2/CoreStorage handling with the owner's credentials against the image · transform resolved on the copy · verified extraction |
The decode: interrupted encryption, why it isn't an attack, and why the data survives
What actually happened, confirmed: his terminal reading was exactly right. That era's macOS could begin converting a volume to full-disk encryption — a background process that rewrites the volume block by block into encrypted form — and a known bug of the version could halt that conversion partway, especially around a crash or panic like the one he suffered. The result is a volume stuck in a half-transformed state: partly encrypted, partly not, its bookkeeping mid-transition, and therefore unmountable — the system can't make sense of a volume caught between two forms. His "it stopped for some strange reason" and "common issue with that version" together nailed the diagnosis before the drive arrived.
Why this is nothing like ransomware — an important reassurance: the word "encryption" alarms people, so this deserves stating plainly. This encryption was your own Mac's, initiated by the operating system as a legitimate security feature, using your own credentials — not an attacker's lock, not a ransom, nothing hostile. There is no criminal, no key held to ransom, no payment. It is a self-inflicted, benign process that failed to finish. That distinction is the whole difference between an unrecoverable extortion (as another file in this volume documents) and this: a routine, completable transformation, provided the legitimate credentials are available — which, as the owner's own volume encrypted with the owner's own password, they are.
Why the data is intact: a half-encrypted volume hasn't lost anything — every block is present, some in encrypted form, some in plain, all accounted for. The barrier is purely that the volume can't be mounted in its in-between state. Reach it correctly — with the owner's credentials, working on an image, either completing the encryption or reversing it to expose the plain data — and the contents emerge whole. His three years of leaving it untouched cost nothing: an unpowered SSD holds its state indefinitely, and the stalled transform simply waited.
The recovery: the half-done process safely finished
The volume was imaged write-blocked in its partially-encrypted state — freezing the delicate in-between condition against any change. Its encryption progress was analysed, the owner's legitimate credentials handled under his authorisation, and the transform resolved on the image: the interrupted conversion carried to a coherent state so the volume could finally be read, exactly the completion the operating system had failed to perform three years earlier. The data mounted from the resolved image and was extracted and verified — intact, having only ever been stuck, never lost.
On the bench
The delicate in-between state was frozen first — the volume imaged write-blocked on the Atola TaskForce 2 — because a half-converted encryption is exactly the structure one does not experiment on in place. The resolution then ran in Passware Kit Forensic, whose FileVault2 support works directly against disk images: the conversion state analysed, the owner's own password applied under his authorisation, and the stalled transform resolved on the copy until the volume mounted coherent. Passware's ordinary forensic role is recovering access the hard way; here it simply finished, safely, the sentence his operating system had abandoned three years mid-word.
The outcome
The data recovered and delivered on new media, and his excellent investigation formally confirmed: interrupted OS encryption, a known bug of the version, no attack, no permanent loss. Free assessment, one fixed written figure including VAT, no recovery, no fee. His terminal work had diagnosed the case correctly; this page's part was to safely finish what his Mac had abandoned mid-sentence.
Volume won't mount, and encryption looks half-finished
Don't panic at the word "encryption": if it was your own Mac's disk-encryption that stalled — as a known bug of older macOS versions could cause around a crash — this is benign and completable, not ransomware, and your data is stuck rather than lost. Stop trying to mount or repair it; a half-transformed volume is delicate, and repair attempts can disturb the in-between state. Keep the drive as-is (unpowered SSDs hold indefinitely). And have it imaged and the transform resolved on the copy, using your own credentials — the process just needs finishing safely, which is exactly what the failed conversion never got to do.
Stuck, not lost — call Edinburgh Data Recovery on 0131 202 0491; the transform finished safely on a copy, one written figure, no recovery, no fee.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.