Microsoft provided the FBI with BitLocker recovery keys to decrypt data on three seized laptops as part of a federal investigation in Guam into alleged fraud tied to the Pandemic Unemployment Assistance program, according to reporting cited by both TechCrunch and DataBreaches.net (via Forbes). The reporting highlights that BitLocker full-disk encryption is enabled by default on many modern Windows systems and that recovery keys may be uploaded to Microsoft’s cloud by default or by user choice, enabling Microsoft to produce those keys in response to lawful process.
The case has been framed as a broader privacy and security concern: cloud-stored recovery keys can be obtained via subpoenas/warrants and could also become a target if attackers compromise cloud infrastructure. TechCrunch cited cryptography expert Matthew Green warning that a breach of Microsoft’s cloud could expose recovery keys (though physical access to the encrypted drives would still be required to use them), and reported Microsoft told Forbes it receives an average of roughly 20 law-enforcement requests per year for BitLocker recovery keys.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
In statements cited across follow-on coverage, Microsoft said it may provide BitLocker recovery keys to authorities when presented with valid legal process, but only when customers have stored those keys in Microsoft's cloud. The company emphasized that users can choose other key-management methods that leave Microsoft unable to assist.
Forbes published the first widely cited report that Microsoft had provided BitLocker recovery keys to the FBI in the Guam fraud investigation. The report also said Microsoft told Forbes it receives about 20 such law-enforcement requests per year on average.
A 2025 court document cited in later reporting said an ICE forensic expert stated the agency lacked tools to defeat BitLocker encryption without the recovery key. The filing underscored that access to Microsoft-held recovery keys was operationally significant to the investigation.
Microsoft complied with the warrant and provided cloud-stored BitLocker recovery keys for the three laptops, allowing federal investigators to unlock the encrypted drives. Reports describe this as the first publicly known case in which Microsoft disclosed BitLocker keys that directly enabled law enforcement access to device data.
In early 2025, the FBI served Microsoft with a search warrant seeking BitLocker recovery keys for three laptops tied to a Guam investigation into alleged COVID-19 Pandemic Unemployment Assistance fraud. Investigators needed the keys because the seized devices' drives were protected by BitLocker full-disk encryption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
12 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcecyberscoop.com
Open sourcezdnet.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcetechcrunch.com
Open sourcedatabreaches.net
Open sourceforbes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.