Encrypted APFS recovery deserves a clear, practical explanation. FileVault is on by default on modern Macs, which means most Mac recovery jobs are now encrypted-volume recovery jobs whether anyone planned it that way or not. The good news is that having the password changes everything. The bad news is that plenty of people scan the encrypted container by mistake, find nothing, and conclude their data is gone.
The short answer. Unlock the volume first, then scan. An unlocked APFS volume behaves like any other volume and recovery works normally. Scanning a locked container gets you nothing but random bytes, no matter how good the software is.
Encrypted APFS recovery: Unlock before you scan
However, In Disk Utility, select the volume and choose Unlock, or from Terminal use diskutil apfs unlockVolume. Once it is unlocked, macOS presents the decrypted contents through a virtual device, and that device is what your recovery software should target. If the tool shows you a volume that is entirely unreadable noise, you picked the wrong one — go back and choose the unlocked one.
For example, This is also why booting from an external installer and running recovery from there is often easier than trying to scan the internal drive of the Mac you are using. You can unlock the internal volume from Recovery Mode and work on it while nothing is writing to it.
What happens without the password
As a result, Nothing. That is the honest answer and it is worth saying plainly, because there are products that imply otherwise. AES-256 with a key derived from your password is not something a consumer tool brute-forces. If the password is genuinely lost and there is no recovery key and no institutional key escrow, the data is unrecoverable. Not difficult — unrecoverable.
- Check iCloud Keychain. FileVault recovery keys are often stored there.
- Check whether the Mac is managed by an employer. Corporate MDM usually escrows the key.
- Check for a printed recovery key. Ventura and later prompt you to save one during setup.
- If none of those exist, the volume is closed permanently. Plan around that rather than paying someone who claims otherwise.
Apple Silicon adds a wrinkle
In addition, On M-series Macs the internal SSD is tied to the Secure Enclave on that specific machine. You cannot pull the drive and read it elsewhere, even with the password, because the hardware key lives in the chip. Recovery has to happen on that Mac, booted into Recovery Mode or Target Disk Mode. Plan accordingly — if the logic board is the thing that failed, this is a professional job, not a software one.
| Situation | Recoverable with software? | Notes |
|---|---|---|
| Unlocked volume, deleted files | Yes | Standard APFS recovery |
| Locked volume, password known | Yes | Unlock first, then scan |
| Locked volume, password lost | No | Genuinely no. Check for a recovery key |
| Apple Silicon, board failed | Not with software | Apple or a specialist lab |
| Intel Mac, T2 chip, password known | Yes, on that Mac | Cannot read the SSD externally |
| External encrypted drive, password known | Yes | Easiest case — unlock and scan |
Scanning an unlocked APFS volume
Once the volume is unlocked, the job is ordinary APFS recovery — and APFS snapshots and clone files mean a decent tool can often reconstruct more than you expect. Stellar Data Recovery handles APFS natively, including encrypted volumes you have unlocked, and previews files before recovery so you can confirm they decrypted cleanly.
One habit worth adopting
Write your recovery key down and put it somewhere physical. Not a note on the desktop of the encrypted machine. The number of people who have lost data to their own encryption is not small, and it is entirely preventable with an index card in a drawer.