Microsoft handed BitLocker keys to the FBI under legal order

Microsoft has acknowledged that in a recent legal case it supplied the FBI with BitLocker recovery keys after receiving a valid legal order. The keys allowed the FBI to unlock and access data on three BitLocker-encrypted Windows laptops seized in February 2025 in a fraud investigation in Guam. The case is the first publicly confirmed instance of Microsoft handing BitLocker keys to law enforcement, and the company says it receives around 20 such requests a year, many of which cannot be fulfilled because users have not backed up keys to Microsoft's cloud. The case raises questions about cloud-based key storage creating a route around disk encryption.

What this means for your organisation

Disk encryption is one of those controls organisations document and then stop thinking about. This case sharpens what the control actually protects against. Encryption holds against a thief with a stolen laptop, but it does not hold against someone who obtains the recovery key. Where that key sits, who controls it and under which jurisdiction is therefore something leadership should have a considered answer to, particularly for machines holding business-critical or personal data.

Berigo recommends

  • Establish where your BitLocker recovery keys are actually stored today and who can access them.
  • Consider self-managed key storage for machines holding your most sensitive data rather than the cloud default.
  • Bring jurisdiction over keys and secrets into your cloud risk assessment.
  • Describe in your privacy documentation how key management affects protection of personal data on endpoints.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch