MacBook Data Recovery: Process and Limits on the T2, M1, M2 and M3 Chips
In modern MacBooks the SSD is soldered to the logic board. On the T2 and Apple Silicon M1/M2/M3, the Secure Enclave performs AES-256. If the password is lost, the data cannot be decrypted even if the NAND is read. For logical damage, Time Machine plus Migration Assistant. For physical damage, micro-soldering repair plus a mandatory Apple ID.
MacBook Data Recovery: Process and Limits on the T2, M1, M2 and M3 Chips
TL;DR: In modern MacBooks the SSD is now soldered to the logic board and is no longer a removable part. On T2-equipped Intel models and on Apple Silicon models with M1, M2, M3, and M4 processors, the Secure Enclave performs hardware AES-256 encryption. If the user password or FileVault password is lost, the NAND content cannot be decrypted even if it is physically read. For logical damage, recovery via Time Machine or Migration Assistant is easy. For physical damage, the data comes out in most cases, but the Apple ID or device password is absolutely required.
This section of the main Data Recovery Guide 2026 article, focused on the MacBook family, explains the hardware lock reality brought by the T2 and Apple Silicon architecture. For the iPhone side, see iPhone dropped in water.
SSD Architecture Across MacBook Models
Apple has used four different generations of storage architecture over the past decade. Each generation's recovery behavior is different.
Before 2015 (removable SSD). In pre-2015 MacBook Pro and MacBook Air models, the SSD was installed as a separate card. In the event of a logic board failure, it was possible to remove the SSD and install it in another Mac or connect it to an external adapter. Data recovery on these models is the closest to classic PC logic.
2016 to 2017 (PCIe modular). On the MacBook Pro models of this period, the NVMe PCIe SSD was connected to the logic board with a very special connector. Because it was modular, removal was still possible, but since encryption was active at the software layer, passwordless access was blocked for users with FileVault enabled.
T2-equipped MacBooks after 2018. Apple made the T2 security chip standard in the MacBook Air 2018, MacBook Pro 2018 and later, iMac Pro, and Mac mini 2018 models. From this generation onward, the NAND chips are soldered directly to the logic board. Decryption is performed entirely in the Secure Enclave inside the T2.
Apple Silicon M1, M2, M3, and M4 after 2020. On Apple Silicon Macs, the NAND, controller, and Secure Enclave are integrated into a single SoC cluster. Installing the device's NAND chip in another Mac or connecting it to another SoC does not technically work, because the key was generated on a different chip.
The Apple Platform Security documentation (https://support.apple.com/guide/security/welcome/web) explains this architecture step by step, and the general Apple Support technical reference (https://support.apple.com) provides the support matrix by model.
Apple Silicon (M1, M2, M3) Secure Enclave
On Apple Silicon processors, each device has a unique UID key. This key is written to the Secure Enclave Processor during manufacturing and never leaves it. The user password is mixed with the UID to derive a kind of key, and all the data on the NAND is encrypted with AES-256.
The practical result is this: even a laboratory that manages to remove the NAND chip and read it raw cannot decrypt the data without the user password and the UID combining. Because the UID never leaves the Secure Enclave, when the logic board burns out or the SoC physically dies, the key is also lost. For this reason, on Apple Silicon Macs there is no such thing as data recovery without logic board recovery. If the logic board is revived and the user knows the password, the data comes out, otherwise it does not.
Since JEDEC (https://www.jedec.org) is the organization that publishes NAND flash memory standards, it is a reference for the technical definition of NAND reading processes, but this standard does not decrypt encrypted content, it only reads the raw cells.
The T2 Chip (Intel MacBook 2018-2020)
The T2 is the first hardware security chip Apple used in Intel Macs. It combines the SSD controller, image processor, system management controller, and Secure Enclave functions in a single package.
On a T2-equipped MacBook Pro or MacBook Air, hardware encryption is always active on the SSD. Even if FileVault is not active, the data is encrypted with the T2 key. In this case, removing the NAND without the Apple ID or user password yields nothing. The iMac Pro, Mac mini 2018, and MacBook Pro 2018 and later models share the same architecture.
The fundamental difference between the T2 and Apple Silicon is the processor architecture (Intel x86 vs ARM), but from a data recovery standpoint the user experience is the same. In both, the key is in the Secure Enclave.
Logical Damage Recovery (Deletion, Format, System Corruption)
If the device is operational and there is only file loss, there are still many paths.
If There Is a Time Machine Backup
Apple Support guidelines recommend using Migration Assistant in cases where a Time Machine backup is available. A restore is performed from the Time Machine disk to a new or formatted Mac. The user account, applications, and documents come back as they were. This is the safest path.
iCloud Drive Synchronization
In macOS Ventura and later, the Documents and Desktop folders can be synced with iCloud Drive by default. Even if the Mac has been formatted, the data is pulled back via iCloud.com or by signing in on a new device. An Apple ID and two-factor authentication are required.
Mounting with Disk Utility
If the disk is still recognized but macOS will not boot, the volume is examined with Disk Utility in Recovery Mode. The list of APFS partitions is obtained, a dmg image is extracted if needed, and the files are recovered one by one by mounting it on an external disk. This approach works in cases of system file corruption.
Data Recovery Software
Tools such as Disk Drill, R-Studio for Mac, and EaseUS Mac Data Recovery support the APFS file system. These programs re-list logically deleted files. The important condition: the disk must still be recognized by macOS. On T2 or Apple Silicon Macs, if the hardware has physically died, no software can see the data because the logic board is not decrypting it.
Physical Damage Recovery
Liquid Contact, Drops, Logic Board Burnout
Liquid can get inside through the cooling fan gaps, the keyboard slits, or the connection ports. Corrosion begins on the PCB. Laboratories that perform electronic repair at the micro-soldering level clean the PCB, replace the oxidized components, and try to revive the device. If the device can be booted successfully even once and the user password is known, the data is extracted via methods like Migration Assistant or Target Disk Mode. On Apple Silicon, the Share Disk feature is used instead of Target Disk Mode.
Cracked Screen
A cracked screen does not directly affect the data. The device is connected to an external monitor via HDMI or USB-C, runs normally, and the data is transferred to an external disk. If the user knows the Apple ID password, this operation is completed in a few hours.
Keyboard or Trackpad Liquid Contact
In MacBooks the keyboard and trackpad are connected to the logic board via a flex cable. On liquid contact, the keyboard plug usually oxidizes but the logic board remains intact. The system is accessed by connecting an external keyboard or signing in via Bluetooth, and the data is extracted.
DFU Restore with Apple Configurator 2
Apple Configurator 2 (https://support.apple.com/apple-configurator) makes it possible to restore firmware via DFU (Device Firmware Update) mode on T2 and Apple Silicon Macs. The target device, connected to a second Mac via USB-C, is put through a Revive (re-vival, preserves data) or Restore (full restore, erases data) operation through Apple Configurator 2.
In a data recovery scenario, a Revive attempt is always done first. If the device revives and macOS boots, the data becomes accessible. Restore, as long as it does not erase the NAND, is used as a last resort because it erases all user content.
Why Is NAND Chip-Off Impossible on Apple Silicon?
On traditional phones and older SSDs there is the chip-off technique: the NAND chip is removed, connected to a programmer, and the raw data is read. On Apple Silicon and T2 Macs this method does not work, because:
- The raw data read from the NAND is encrypted with AES-256.
- The encryption key is not inside the NAND, it is inside the Secure Enclave.
- The Secure Enclave UID value never leaves the chip.
- When the device that generates the key dies, the key dies too.
As a result, even if NAND chip-off is technically performed on Apple Silicon Macs, it does not yield meaningful data output. This situation is clearly written in the Apple Platform Security documents.
Apple Service vs Digital Forensics Laboratory
Apple Authorized Service Providers perform device replacement, logic board replacement, or comprehensive repair. By Apple's official policy, they do not offer a data recovery service, and the data on a logic board replaced under warranty is lost.
Digital forensics laboratories are different. These laboratories perform repair at the micro-soldering level, replace the capacitors and ICs on a damaged PCB one by one, and give the device temporary life. The aim is not to make the device sellable, only to open it enough to be able to extract the data. The warranty is sacrificed in this process.
When the FileVault Password Is Forgotten
FileVault is macOS's software-layer encryption and is added on top of the T2 and Apple Silicon hardware encryption.
When the FileVault password is forgotten there are three possibilities:
- If the Recovery Key created during setup was saved, the volume is opened with this key.
- The FileVault recovery key may have been backed up to iCloud Keychain. It is reached via the Apple ID.
- If neither exists, no one but the device's user can know the password, brute force is not feasible in a reasonable time mathematically, and the data is considered lost.
When the Apple ID Password Is Lost
The Apple ID is the key to iCloud backup, iCloud Drive, and Find My access. When the password is lost, the account recovery process is started through Apple Support. Apple uses the trusted device, trusted phone number, and Recovery Key steps in two-factor authentication.
According to Apple records, the Account Recovery process can take one to two weeks to complete. During this time the iCloud backup remains inaccessible. When the Apple ID account recovery process is finished, iCloud Drive and backup access are opened with the new password.
The Process Step by Step
- Device diagnosis. Is the Mac receiving power, does the screen turn on, does it enter DFU mode? A connection is attempted with Apple Configurator 2.
- Clarifying the password situation. Are the user password and Apple ID password available, is FileVault active?
- Logical or physical category. For a software fault, the Time Machine, Migration Assistant, and data recovery software path. For physical damage, micro-soldering repair.
- Written approval. The process, cost, and likelihood of success are presented to the customer in writing, and approval is obtained.
- Data extraction. The Apple ID sign-in is performed, and copying to an external disk begins.
- Verification. It is confirmed that the extracted files can be opened and read.
- Delivery. The data is delivered to the customer on an encrypted disk.
- KVKK-compliant destruction. The temporary copies are erased with the NIST SP 800-88 Purge procedure.
KVKK and Privacy
A MacBook can contain content at the level of personal data, employee records, financial documents, and company secrets. Under the KVKK (https://www.kvkk.gov.tr) law, protecting this content during data recovery is the service provider's responsibility. An NDA is signed, the laboratory works air-gapped (isolated from the internet), a chain of custody is kept, and after delivery the temporary images are erased with the NIST SP 800-88 Purge method.
FAQ
My MacBook screen is cracked, will the data come out?
Yes. An external monitor is connected, the system is accessed with the user password, and the data is copied to an external disk. A cracked screen is only a display problem.
I forgot my FileVault password, will it come back?
If there is a Recovery Key or an iCloud Keychain backup, yes. If neither exists, AES-256 brute force is not feasible in a reasonable time, and the data is considered lost.
There's no Apple ID password but there's an iCloud backup, can it be opened?
The Apple Account Recovery process is started. The account can be recovered in one to two weeks with a trusted device, phone number, or Recovery Key. At the end of this period the iCloud backup can be downloaded.
The logic board burned out, does removing the NAND help?
On Apple Silicon and T2 models, no. Because the encryption key remains in the Secure Enclave, the removed NAND gives raw encrypted data that cannot be decrypted. The only hope is reviving the logic board.
It was formatted with no Time Machine backup, can it be recovered?
After an APFS format, the NAND is usually physically erased (TRIM and secure erase are in play). On Apple Silicon, a format generally means permanent loss of the content.
Is there a difference on an M2 or M3 MacBook compared to the T2?
The architecture is different (the T2 is an Intel support chip, the M series is a full SoC), but from a data recovery standpoint both use Secure Enclave-centric AES-256. The user experience is the same.
How long does data recovery take?
Logical cases usually take one to three days. Physical damage and micro-soldering repair can take one to three weeks. The Apple ID account recovery process can add another one to two weeks.
Working with DSET
The most important point to watch in the MacBook data recovery process is documenting the password and Apple ID situation before powering the device. A wrong intervention permanently loses the data on Apple Silicon Macs.
For more comprehensive scenarios, the main article Data Recovery Guide 2026 covers them. For the iPhone side, the iPhone dropped in water article is a separate guide.
The DSET laboratory, at the Hacettepe Teknokent Ankara address, provides MacBook T2 and Apple Silicon data recovery service with a KVKK-compliant process. The preliminary analysis is free, and no fee is charged in cases that do not conclude with a result approval.
Contact: Hacettepe Teknokent, Ankara, +90 536 662 38 09.
Sources:
- Apple Support, https://support.apple.com
- Apple Platform Security, https://support.apple.com/guide/security/welcome/web
- Apple Configurator 2, https://support.apple.com/apple-configurator
- JEDEC, https://www.jedec.org
- KVKK Law, https://www.kvkk.gov.tr
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.