Locked M2 MacBook After a Scam: Recover Credentials Before Paying a Data-Recovery Lab
This is primarily a credential-recovery problem, not a normal disk-recovery problem. If an M2 MacBook still reaches the login screen but the known account and administrator passwords no longer work, do not erase it and do not assume a recovery lab can remove the internal storage and read the files elsewhere.
In this MacBook repair case, a friend’s M2 MacBook Air was compromised in a scam, the passwords were changed, and the machine still booted to a login screen. Recovery also requested an administrator password, while the expected “Forgot all passwords?” path was not available. After Apple reportedly said data recovery was not possible, another provider quoted about $1,350.
Try Authorized Password Recovery Before Paying a Lab
Apple’s current Mac login-password recovery guidance lists several legitimate recovery paths, but which ones appear depends on how the Mac was configured. Before doing anything destructive, check for:
- Apple Account reset options: After repeated failed logins, the Mac may offer an Apple Account–based reset if that recovery path was configured.
- FileVault recovery key: If FileVault is enabled, the recovery key may unlock the recovery workflow. On newer macOS versions, Apple says the key may also be available in the Passwords app on another trusted device signed in to the same Apple Account.
- Another authorized administrator: If another admin account exists and can still sign in, it may be able to reset the affected account.
- Recovery reset flow: Apple documents additional password-reset options from macOS Recovery, including the
resetpasswordworkflow when Terminal is available.
If the scam may also have compromised the Apple Account, follow Apple’s compromised-account recovery guidance from a separate trusted device rather than experimenting on the affected Mac.
What a Data-Recovery Lab Cannot Promise
Apple documents that internal storage on Apple silicon Macs uses hardware-backed encryption. When FileVault is enabled, valid login credentials or a cryptographic recovery key are required to unlock the protected APFS volume. The encryption-key hierarchy is tied to the Secure Enclave, so moving or directly reading the internal storage is not equivalent to reading an ordinary removable SSD.
That means a reputable lab should be able to explain what authorized access path it expects to use. A quote is not a recovery method. Ask whether the lab expects an Apple Account/FileVault credential, is repairing a hardware fault that blocks normal authentication, or is simply charging for diagnosis. If the Mac already boots normally to the login screen, a claim that the lab can “bypass” Apple silicon encryption without valid authorization deserves particular scrutiny.
Before Paying the Quote
- Ask for the exact plan: What is preventing access, and what will the lab do that Apple’s authorized password-recovery paths cannot?
- Ask about no-data fees: Confirm the amount owed if the files remain locked.
- Keep the original Mac intact: Do not authorize Erase Mac or a factory restore while the local files are the only copy.
Why Erasing the Mac Ends This Recovery Path
Apple states that if password recovery fails, Erase Mac can restore access to the computer—but it permanently removes the user accounts, passwords, and local data. That is a device-reset option, not a data-recovery step.
Recoverit also cannot bypass a locked FileVault or Apple silicon volume. Its FileVault data-recovery guidance applies only after the encrypted volume can be unlocked with an authorized password, recovery key, or managed recovery method.