A recent incident posted on Reddit highlights an unexpected side effect of Windows 11. One user described how, after reinstalling the operating system, he found himself with two external drives encrypted via BitLocker, without ever having enabled the feature. The result? More than 3TB of valuable files were permanently locked, with no way to access them.

The "silent" activation of BitLocker
BitLocker is Microsoft's full disk encryption tool, designed to protect data in the event of theft or unauthorized access . However, in Windows 11 Pro and Enterprise editions, and especially in the 24H2 update , the feature can be automatically enabled if certain technical criteria are met, such as TPM 2.0 support and Secure Boot .
This "smart" security, intended to protect users, has a dark side: it activates without warning, even during a simple reinstall. The result is that disks used for storage or backup may inadvertently be encrypted, locking data behind an unknown recovery password.
See also: CISA added five new vulnerabilities to the KEV List
From resettlement to chaos
With a powerful system (AORUS B550 Elite AX v2 motherboard, AMD Ryzen 7 5700X3D processor, 64GB of RAM, and NVIDIA GeForce RTX 3060 GPU), the unfortunate Reddit user decided to perform a clean install of Windows 11 to fix performance issues. However, after completing the process, the D: and E: drives—which contained backups—appeared locked with BitLocker, asking for a recovery key that was nowhere to be found.
Initial recovery attempts failed. Tools like UFS Explorer and Stellar Data Recovery Professional failed to read the encrypted files. The instructions circulating online, almost all of them, concern cases where BitLocker has been enabled on the boot drive, not on secondary storage drives like here.

In desperation, the user resorted to unofficial programs and torrents to break the encryption — which ultimately led to a malware infection and a second forced reinstall of the operating system.
What's really wrong?
There is no officially identified technical bug linking specific hardware (such as AORUS motherboards or Ryzen processors) to this phenomenon. However, multiple reports indicate that AMD Ryzen systems with compatible motherboards can trigger it if BIOS settings such as fTPM are enabled.
See also: Dolby Digital Plus: Vulnerability allows RCE attack
BitLocker recovery options include a 48-digit recovery password stored in your Microsoft Entra ID, Active Directory, or printed files, a .bek recovery key file, or a key package for damaged drives. However, none of these apply here.
Without them, accessing encrypted data is almost impossible, as the encryption uses AES-128 or AES-256 standards that resist brute-force attacks.
Finally, after hours of frustration, the user formatted the drives, erasing years of data, with only old backups available.
Security at the cost of convenience
Microsoft has invested in the idea that default encryption makes Windows more secure. However, the lack of end-user awareness makes this feature a trap for those who don't know how BitLocker works.
Additionally, the software-based feature can significantly slow down SSDs, up to 45%, especially on systems without a separate TPM chip. So a feature aimed at security can impact both performance and user experience.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: PoC exploit released for Linux-PAM vulnerability

How to protect yourself
Experts recommend a few steps to avoid a similar nightmare:
- Disable BitLocker before or immediately after installing Windows, via Control Panel or PowerShell.
- If you use USB creation tools like Rufus, set them to disable automatic encryption.
- Back up your recovery keys to secure external media or to your Microsoft account.
- Check Group Policy for encryption defaults before using new drives.
For Home users , BitLocker is not native, but upgrading to Pro introduces these risks. As Windows 11 evolves, Microsoft's push for default encryption prioritizes security over user awareness, underscoring the need for proactive data management.
A lesson for everyone
The incident is not an isolated one. As Microsoft increasingly promotes built-in security, the need for users to be informed. Automatic protection is not a panacea — when applied without warning, it can end up destroying the very data it was intended to protect.
The Reddit user's case is a reminder that, in the age of cybersecurity, information is the most important tool we have.
