Data Recovery from a Locked or Encrypted Phone: Screen Passcode, FBE Encryption and Forensic Unlock

Quick answer: Recovering data from a locked phone is a completely different problem from a broken or water-damaged phone. The device works physically, but the screen passcode is unknown or the data is locked with hardware-based encryption. On modern phones data is decrypted not when the device powers on but when the correct passcode is entered; so even if data is read without the passcode, it is encrypted and meaningless. On Android, file-based encryption (FBE) ties the key to the user's screen lock; on iPhone, the Secure Enclave protects the key and rate-limits wrong attempts in hardware. So the way to recover data from a locked phone is usually not physical repair but either knowing the passcode or the specific device/version combinations supported by forensic unlock tools like Cellebrite. Honestly: on many current devices with a strong passcode, recovery may be impossible, and this should be said plainly.

When a phone's screen cracks or it falls in water, the problem is in the hardware and can be solved by repair; we covered this in phone won't turn on, cracked screen recovery and phone fell in water first response. A locked phone is a different world: the hardware is intact, the real obstacle is cryptography. This article addresses the "the phone works but I cannot open it" situation, how modern encryption works and the realistic expectation.

Why modern phone encryption is so strong

A decade ago, recovering data from a phone usually meant removing the chip (chip-off) and reading the raw memory. Today this has changed, because both Android and iOS encrypt all user data by default and tie the encryption key to the user's screen lock.

On Android, file-based encryption (FBE), defined in the AOSP documentation, encrypts each file with different keys, and credential-encrypted storage is decrypted only after the user unlocks the screen. So even if you power the device on, user data stays encrypted until the passcode is entered.

On iPhone, per Apple Platform Security documentation, encryption keys are protected by the Secure Enclave, a separate security chip on the mainboard. The Secure Enclave combines the passcode with the hardware identity; so even if the memory is moved to another device the key does not come out, and wrong passcode attempts are delayed at the hardware level. This makes quickly trying millions of combinations (brute force) practically impossible.

The "I read the data but it is encrypted" problem

The practical consequence of this architecture is: physically reading the memory of a locked phone (for example with chip-off) no longer works on its own, because the data obtained is encrypted. We explained what chip-off is and when it is still valuable in what is chip-off, who does it and eMMC/UFS embedded storage data recovery. On an encrypted device, removing the chip usually gives only a meaningless pile of encrypted bytes; without the key this data cannot be decrypted.

So on a locked phone the real question is not "how do I read the memory" but "how do I get the key." The key can be reached in three ways: knowing the correct passcode, exploiting a weakness supported by the manufacturer or a forensic tool, or, if none exist, honestly not recovering the data.

Forensic unlock tools: what they can and cannot do

Cellebrite, GrayKey and similar mobile forensic tools offer passcode cracking or lock-bypass methods for specific device model and operating system version combinations. These are not magic: they are always limited to a specific device/version/patch level, are in a constant cat-and-mouse with manufacturer security updates, and are usually licensed only to authorized bodies (law enforcement, forensic labs). We explained in detail what Cellebrite UFED is, its scope and its licensing situation in Turkey in what is Cellebrite UFED, mobile forensic alternatives and Cellebrite UFED Turkey institutions licensing.

The critical truth is: the list of devices these tools support constantly changes. While an old Android or a specific iOS version is supported, the latest device with a strong passcode is usually not supported. So "Cellebrite opens every phone" is not true; what they can open depends on gaps the manufacturers have not yet closed.

Realistic expectation and honesty

The most important principle in data recovery is honesty: on a current phone that is locked and encrypted with a strong passcode, recovery is often impossible. A service that tells you "we open every locked phone" is either mistaken or misleading. At DSET we first determine the device model, operating system version and patch level, and honestly say whether known methods apply to that combination. In some cases (a simple pattern lock, a known weakness, or the owner knowing the passcode) recovery is possible; in some it is not.

An important note: trying to open an unauthorized device is a legal matter. Forensic examination or unlocking of a phone is done only at the request of the device owner or an authorized body (court, prosecutor), with written authorization. For the legal framework of the forensic process see the digital forensics process, KVKK and chain of custody.

What to do and not do with a locked phone

  1. Do not turn the device off. On modern phones, data is more deeply encrypted on the first boot after a restart (before first unlock state); a device that is on and has been unlocked once is more amenable to some methods.
  2. Do not guess the passcode. Many wrong attempts can trigger delay, lockout or data wipe on some devices.
  3. Check backups. Even if the actual data is locked on the phone, an iCloud, Google or computer backup may be the easiest way to reach the data; see iCloud data recovery.
  4. Authorization and ownership. Have the examination done only at the owner's or an authorized body's request, with written permission.
  5. Expert assessment. Have an expert determine the device model and version and give a realistic success expectation.

BFU and AFU: the device's two lock states

One of the most critical concepts in modern forensics is the device's two different lock states, and this directly determines the chance of data recovery.

BFU (Before First Unlock): If the phone was just powered on or restarted and the user has not entered the passcode even once, almost all user data is in its most deeply encrypted state. In this state the keys are not decrypted in memory, so even if the device is accessed the data cannot be read. On iPhone this is the most secure state.

AFU (After First Unlock): If the user has entered the passcode at least once after the device powered on, many encryption keys are kept decrypted in memory until the device is turned off. In this state the device is much more amenable to some forensic methods, because the data is partially accessible.

The practical consequence is: if you have a locked but powered-on and previously used device, do not turn it off and do not restart it. Turning it off returns the device from the AFU state to the BFU state and can seriously reduce the chance of recovery. This explains why a well-meaning but harmful mistake like "we found the phone, turned it off and brought it in" matters so much.

Pattern, PIN and password: how strong is each

The type of screen lock directly affects how protected a device is, because the encryption key is tied to this lock.

  • Pattern lock: Relatively weak; the number of possible patterns is limited and on some old devices a pattern is more fragile than a password.
  • 4-digit PIN: Only ten thousand possibilities. Without hardware rate limiting it would be quickly brute-forced; what protects the device is the hardware that slows down wrong attempts.
  • 6-digit PIN: A million possibilities; much stronger than a PIN but still behind a strong password.
  • Alphanumeric password: A long password with letters, numbers and symbols raises the number of possible combinations to an astronomical level and, combined with hardware rate limiting, becomes practically uncrackable.

So a device's recoverability depends not only on the model and version but also on the lock type the user chose. An old phone with a 4-digit PIN and a current phone with a long password are two completely different problems.

Real-world scenarios

In our field experience, locked-phone requests come in a few typical scenarios, and each has a different legal and technical answer.

A deceased relative's phone: The family wants to reach the photos or personal data inside. Here both the technical limit (if the device is current and has a strong password it may not be opened) and the legal framework (inheritance and authorization) are evaluated together. Often a cloud backup is a more accessible route than the device itself.

A forgotten own password: The person has forgotten the password of their own device. This is the most legitimate scenario, but unfortunately also the hardest on a modern device; the manufacturer locks even the owner behind the lock. Here too, backups are the first place to look.

A corporate device: A company-owned device used by an employee. Here the company's ownership and mobile device management (MDM) policies come into play; often a reset or access is possible through corporate management.

A stolen or found device: In this case the authority to examine belongs only to law enforcement; it cannot be handled as an individual service.

In every case DSET's first step is the same: identify the device, clarify the legal authorization and honestly state a realistic success expectation.

Frequently Asked Questions

If you remove and read the memory of a locked phone, do you get the data? On a modern encrypted device, no; the data obtained is encrypted and cannot be decrypted without the key. Chip-off is meaningful only on old, unencrypted or weakly protected devices.

Does Cellebrite open every phone? No. The devices it can open depend on the model, OS version and patch level and constantly change; the latest devices with a strong passcode usually cannot be opened.

I know the passcode but the screen is broken, can the data be recovered? That is now a hardware problem and can usually be solved; see cracked-screen phone data recovery.

Can I have someone else's phone opened? Only at the owner's or an authorized body's (court, prosecutor) request, with written authorization. Otherwise it is unlawful.

Sources

For a realistic and honest assessment of your locked or encrypted device, contact DSET.