Monday, August 3, 2026

Policy & Regulation

Microsoft provided FBI with BitLocker keys in fraud investigation

Microsoft provided the FBI with BitLocker recovery keys to unlock three laptops, highlighting privacy concerns regarding the company's default practice of storing encryption keys in the cloud.

Microsoft provided FBI with BitLocker keys in fraud investigation
Photo: Microsoft

Microsoft provided the FBI with the recovery keys to unlock encrypted data on the hard drives of three laptops, Forbes reported on Friday. The laptops were involved in a federal investigation concerning several people suspected of fraud related to the Pandemic Unemployment Assistance program—a U.S. government aid program—in Guam, a U.S. island in the Pacific. Local news outlet Pacific Daily News covered the case last year, reporting that a warrant had been served to Microsoft in relation to the suspects’ hard drives. Kandit News, another local Guam news outlet, also reported in October that the FBI requested the warrant six months after seizing the three laptops, which were encrypted with BitLocker. The case demonstrates how law enforcement can obtain access to encrypted devices by requesting recovery keys stored in the cloud.

The case highlights how Windows full-disk encryption technology, known as BitLocker, operates. Many modern Windows computers rely on full-disk encryption, called BitLocker, which is enabled by default. This type of technology is designed to prevent anyone except the device owner from accessing the data if the computer is locked and powered off. However, by default, BitLocker recovery keys are uploaded to Microsoft’s cloud, allowing the technology giant—and by extension law enforcement—to access them and use them to decrypt drives. Microsoft told Forbes that the company sometimes provides these recovery keys to authorities, receiving an average of 20 such requests per year.

This default cloud storage practice has drawn criticism from security experts. Matthew Green, a Johns Hopkins professor and cryptography expert, raised the potential scenario where malicious hackers compromise Microsoft’s cloud infrastructure and get access to these recovery keys. Green noted that while hackers would still need physical access to the hard drives to use the stolen recovery keys, the practice remains a significant risk. Green wrote in a 2026 post on Bluesky that these concerns have been known for years. “Microsoft’s inability to secure critical customer keys is starting to make it an outlier from the rest of the industry,” Green stated.

Why it matters

The case underscores the tension between default cloud-based security features and user privacy, specifically how Microsoft’s practice of storing BitLocker recovery keys in the cloud creates a potential backdoor for law enforcement and a target for hackers.