Independent testing. We may earn a commission when you buy through links on this site. Learn more

Recovering From an Encrypted APFS Volume When You Have the Password

Encryption does not make recovery impossible, but it does change the order of operations. Do it in the wrong order and you will scan a volume full of noise.

Encrypted APFS recovery deserves a clear, practical explanation. FileVault is on by default on modern Macs, which means most Mac recovery jobs are now encrypted-volume recovery jobs whether anyone planned it that way or not. The good news is that having the password changes everything. The bad news is that plenty of people scan the encrypted container by mistake, find nothing, and conclude their data is gone.

The short answer. Unlock the volume first, then scan. An unlocked APFS volume behaves like any other volume and recovery works normally. Scanning a locked container gets you nothing but random bytes, no matter how good the software is.

Encrypted APFS recovery: Unlock before you scan

However, In Disk Utility, select the volume and choose Unlock, or from Terminal use diskutil apfs unlockVolume. Once it is unlocked, macOS presents the decrypted contents through a virtual device, and that device is what your recovery software should target. If the tool shows you a volume that is entirely unreadable noise, you picked the wrong one — go back and choose the unlocked one.

For example, This is also why booting from an external installer and running recovery from there is often easier than trying to scan the internal drive of the Mac you are using. You can unlock the internal volume from Recovery Mode and work on it while nothing is writing to it.

What happens without the password

As a result, Nothing. That is the honest answer and it is worth saying plainly, because there are products that imply otherwise. AES-256 with a key derived from your password is not something a consumer tool brute-forces. If the password is genuinely lost and there is no recovery key and no institutional key escrow, the data is unrecoverable. Not difficult — unrecoverable.

  • Check iCloud Keychain. FileVault recovery keys are often stored there.
  • Check whether the Mac is managed by an employer. Corporate MDM usually escrows the key.
  • Check for a printed recovery key. Ventura and later prompt you to save one during setup.
  • If none of those exist, the volume is closed permanently. Plan around that rather than paying someone who claims otherwise.

Apple Silicon adds a wrinkle

In addition, On M-series Macs the internal SSD is tied to the Secure Enclave on that specific machine. You cannot pull the drive and read it elsewhere, even with the password, because the hardware key lives in the chip. Recovery has to happen on that Mac, booted into Recovery Mode or Target Disk Mode. Plan accordingly — if the logic board is the thing that failed, this is a professional job, not a software one.

SituationRecoverable with software?Notes
Unlocked volume, deleted filesYesStandard APFS recovery
Locked volume, password knownYesUnlock first, then scan
Locked volume, password lostNoGenuinely no. Check for a recovery key
Apple Silicon, board failedNot with softwareApple or a specialist lab
Intel Mac, T2 chip, password knownYes, on that MacCannot read the SSD externally
External encrypted drive, password knownYesEasiest case — unlock and scan
The pattern is simple: password plus working hardware equals recoverable.

Scanning an unlocked APFS volume

Once the volume is unlocked, the job is ordinary APFS recovery — and APFS snapshots and clone files mean a decent tool can often reconstruct more than you expect. Stellar Data Recovery handles APFS natively, including encrypted volumes you have unlocked, and previews files before recovery so you can confirm they decrypted cleanly.

One habit worth adopting

Write your recovery key down and put it somewhere physical. Not a note on the desktop of the encrypted machine. The number of people who have lost data to their own encryption is not small, and it is entirely preventable with an index card in a drawer.

Written by BV

BV founded UrRecover after losing a memory card full of wedding photos and discovering that most "best data recovery software" rankings were ordered by commission rate rather than results. He now buys the licences, breaks the drives, and publishes what actually got the files back.

Independent recovery guidanceReview safe first steps before choosing software
Read safety guide