Call us — 01223 655015
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Mac & Apple Systems · The Data Is There and Meaningless

Content Recovered After a Key Was Destroyed Comes Back as Exactly That

His enquiry describes a result that looks like a software failure and is not. A machine erased and reinstalled to clear a restart loop, where photographs were backed up and documents were not — and consumer recovery software "comes back as code and gobbledegook." That output is the diagnosis: on a machine of that design, erasing does not remove the content, it removes the key, and what the software found is the content without it.

MediaLaptop with storage integrated into the mainboard and encrypted against a hardware security component — volume erased and system reinstalled; recovered content returning as unreadable data
Reported situationMachine entering a repeating restart cycle following a system update · volume erased by the owner · operating system reinstalled · photographic content recoverable from a separate backup · documents not backed up · consumer recovery software run against the drive · recovered output returning as unreadable data rather than as files
Fault classEncryption key destroyed by erasure — ciphertext physically retained and mathematically uninterpretable; recovered output consistent with content lacking its key
Equipment usedUnreadable output interpreted as ciphertext rather than as software failure · storage architecture and encryption binding established for the machine generation · volume imaged where addressable and key availability established before any recovery was scoped · alternative sources of the same documents enumerated with the owner

The decode: what the gibberish is, and why it will not improve

What machines of this generation do to everything written: encrypt it. Content is transformed on its way to storage using a key held in a hardware security component, and this happens by default rather than by choice.

What erasing such a volume actually does: discards the key. Rather than overwriting hundreds of gigabytes, the system destroys the key, which renders everything uninterpretable instantly.

Why that is a deliberate design rather than a shortcut: it is fast and thorough. An erase that would take hours completes in seconds and leaves nothing readable.

What that means for the recovery software he ran: it worked correctly. It scanned the storage, found data, and returned it — and what is physically stored is the encrypted form.

Why the output looks exactly as it does: encrypted data has no structure. It is indistinguishable from random content, which is precisely what code and gobbledegook describes.

Why no other software will do better: the limitation is mathematical. Every tool reads the same storage and receives the same ciphertext, and none of them holds the key.

Why this is worth saying before he spends anything more: the outcome will not change. Trying further tools, or paying for a recovery on the same basis, produces the same result.

Why the reinstall is not the cause, though it looks like it: the erase preceded it. The content became unreadable at the moment the volume was erased, not when the system was written.

What is genuinely worth pursuing instead: other copies. Documents commonly exist in mail attachments, cloud folders, shared drives and on other machines, and that is where his effort now belongs.

Why the photographs surviving is instructive: they were backed up elsewhere. The same principle recovers the documents if they were ever sent, shared or synchronised.

On the bench

Unreadable output was interpreted as ciphertext rather than as software failure — machines of this generation encrypting content on its way to storage against a key held in a hardware security component, so erasing the volume destroys the key rather than overwriting content, rendering everything uninterpretable instantly. Recovery software therefore returns what is physically stored, which is encrypted data and indistinguishable from random. Alternative sources were enumerated with the owner.

The outcome

Unreadable output read as ciphertext, encryption binding established for the generation, and alternative sources enumerated. Free assessment, one fixed written figure including VAT; where recovery is not possible, nothing is charged. The decode: the software worked. On a machine of that design, erasing discards the key rather than the content — so what it found and returned is your documents without the means to read them, and no other tool will fare differently.

When recovered files come back unreadable

Stop buying further tools — if the output is random-looking rather than damaged, the limitation is mathematical and every tool reads the same storage. On machines that encrypt by default, erasing the volume destroys the key rather than overwriting content, which renders everything uninterpretable in seconds. That's a design decision, not a fault, and it means recovery software finding data and returning gibberish is working exactly as intended. Put your effort into mail attachments, shared folders and other machines instead.

Recovery came back as unreadable data?
Don't buy more tools — call Cambridge Data Recovery on 01223 655015; output assessed as ciphertext or damage, encryption binding established for your machine, alternative sources enumerated. Assessment free either way.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.