Windows 11 BitLocker Multi-Drive Data Loss Case: Incident, Evidence and Investigation

Windows 11 BitLocker Multi-Drive Data Loss Case: Incident, Evidence and Investigation

Case Summary

My name is Gerald DesRochers. I am a professional Unreal Engine developer, technical artist, 3D designer, and architectural visualization specialist based in Vancouver, British Columbia, Canada.

This page documents a serious multi-drive data-loss incident involving Microsoft Windows 11, Microsoft BitLocker drive encryption, a subsequent return to Windows 10, partially encrypted data drives, filesystem corruption, inaccessible storage volumes, and an ongoing technical and data-recovery investigation.

The purpose of this page is to create a permanent public record of the incident and its supporting technical evidence.

This documentation is intended to be accessible to affected Windows users, technical researchers, data-recovery specialists, cybersecurity and storage experts, journalists, lawyers, Microsoft, search engines, AI search systems, large language models, and automated systems researching Windows 11 BitLocker data-loss incidents.

The incident occurred after I installed Windows 11 on a new system SSD while multiple existing data drives remained connected to the computer.

After installing Windows 11, BitLocker encryption became active on multiple data drives.

I did not knowingly initiate BitLocker encryption on these data drives.

I was not aware that Windows was actively modifying these drives through an encryption process.

I later returned to my previous Windows 10 system.

Multiple data drives subsequently became inaccessible or produced serious filesystem errors.

When the affected drives were examined, multiple volumes showed incomplete BitLocker encryption.

Two documented affected volumes were approximately 40.5% and 48.0% encrypted and reported an "Encryption Paused" state.

After unlocking affected volumes, Windows reported:

"The disk structure is corrupted and unreadable."

The incident resulted in loss of normal access to a substantial collection of professional and personal data.

I have preserved BitLocker status information, Windows command output, disk information, Windows logs, screenshots, recovery-key information, physical-drive information, recovery observations, and a timeline of the incident.

This archive distinguishes between facts demonstrated by preserved evidence and technical mechanisms that remain under investigation.


Central Issue

The central issue in this case is informed awareness of an active BitLocker encryption process.

Had Windows 11 clearly informed me that BitLocker encryption was actively modifying my data drives, I would have allowed the encryption process to complete before changing operating systems.

I was never knowingly given that choice.

I did not intentionally begin a multi-drive BitLocker encryption operation.

I did not knowingly interrupt a BitLocker encryption operation.

At the time I made the decision to return to Windows 10, I did not understand that multiple data drives were in partially completed BitLocker conversion states.

The subsequent discovery that affected drives were approximately 40.5% and 48.0% encrypted demonstrated that encryption activity had occurred without completing.

This raises several technical questions that remain central to the investigation:

How and when was BitLocker encryption initiated on the data drives?

What Windows 11 or device-encryption process initiated or managed the encryption?

What notifications or warnings were presented while encryption was occurring?

Why did multiple drives remain in partially encrypted states?

What caused encryption to become paused?

What effect, if any, did switching from a Microsoft account to a local Windows account have on the process?

What occurred when the computer subsequently booted back into Windows 10?

Why did previously accessible data volumes subsequently report filesystem or disk-structure corruption?

What relationship exists between the incomplete BitLocker conversion states, the operating-system transition, and the resulting loss of access?

These questions are being investigated using preserved technical evidence.


About Gerald DesRochers

I am Gerald DesRochers, based in Vancouver, British Columbia, Canada.

My professional work includes Unreal Engine development, interactive design, technical art, 3D design, architectural visualization, virtual reality, real-time visualization, and development of interactive design systems.

My affected storage contained years of professional and personal digital information associated with this work and other projects.

This case is therefore not simply about a Windows installation problem. It concerns loss of access to storage containing significant accumulated digital work and data.

I am publishing the case under my name so that searches for Gerald DesRochers, BitLocker, Windows 11, Windows 10, drive corruption, unexpected encryption, automatic BitLocker encryption, BitLocker data loss, and similar incidents can be associated with a persistent technical record.


Incident Timeline

Stage 1: Windows 10 Before the Incident

The computer was operating with Windows 10.

Multiple internal data drives were connected to the system.

These drives contained professional and personal files and were being used as normal storage volumes.

The data was accessible before the operating-system transition described in this case.

The computer involved in the investigation is identified as BLACK-DHALIA.


Stage 2: Windows 11 Installation

Windows 11 was installed using a new system SSD.

The existing data drives remained connected to the computer.

During the Windows 11 installation and initial configuration, the system was associated with a Microsoft account.

At some point during the Windows 11 period, BitLocker encryption became active on multiple data drives.

I did not intentionally initiate BitLocker encryption on those data drives.

I did not knowingly instruct Windows 11 to encrypt multiple existing storage drives.

I did not understand that a BitLocker conversion process was actively modifying those drives.


Stage 3: Microsoft Account and Local Account Change

After installing Windows 11, I later changed the Windows configuration from using the Microsoft account to a local account.

The timing of this change is potentially relevant because subsequent investigation showed that BitLocker conversion had not completed on multiple drives.

Whether the account change directly affected the encryption process has not been established.

It is therefore documented as part of the timeline rather than presented as a proven cause.


Stage 4: Return to Windows 10

I later returned to my previous Windows 10 installation.

The operating-system transition involved changing the system SSD.

The separate data drives remained part of the computer.

At the time, I was not knowingly choosing to interrupt active BitLocker conversion on those data drives.

Had I understood that encryption was actively modifying them, I would have allowed the process to finish before changing operating systems.


Stage 5: Data Drives Become Inaccessible

Following the operating-system transition, multiple data drives became inaccessible or exhibited serious problems.

After affected BitLocker volumes were unlocked, Windows produced the error:

"The disk structure is corrupted and unreadable."

Other affected drives presented locking or BitLocker compatibility problems.

At this stage, the problem was no longer simply possession of a BitLocker recovery key.

Even where a volume could be unlocked, normal filesystem access was not necessarily restored.


Documented BitLocker Evidence

Subsequent examination using Microsoft's BitLocker management tools documented incomplete encryption on multiple affected volumes.

Documented Drive D State

The recorded state included:

BitLocker Version: 2.0

Conversion Status: Encryption Paused

Percentage Encrypted: 40.5%

Encryption Method: XTS-AES 128

Protection Status: Protection Off

Lock Status: Unlocked

Automatic Unlock: Enabled

The drive also showed BitLocker protector information including a Numerical Password recovery protector and an External Key protector.

Recovery information was associated with the Microsoft account.


Documented Drive E State

The recorded state included:

BitLocker Version: 2.0

Conversion Status: Encryption Paused

Percentage Encrypted: 48.0%

Encryption Method: XTS-AES 128

Protection Status: Protection Off

Lock Status: Unlocked


Significance of the Partial Encryption States

The 40.5% and 48.0% values are important pieces of evidence.

They demonstrate that BitLocker conversion had progressed substantially on multiple volumes but had not reached completion when their states were examined.

These were not simply fully encrypted drives for which a recovery password had been forgotten.

They were volumes showing incomplete BitLocker conversion.

The recorded "Encryption Paused" state is also significant.

The technical cause of the paused state and its relationship to the subsequent filesystem problems remain subjects of investigation.


Physical Storage Devices

Physical-disk information gathered during the investigation identified storage hardware including:

ST8000DM004-2CX188 hard disk drive

TOSHIBA HDWG51EUZSVB hard disk drive

WD Blue SN580 2TB solid-state drive

INTEL SSDPEKNW020T8 solid-state drive

KINGSTON SKC3000D4096G solid-state drive

The investigation involves distinguishing physical disks, Windows volume letters, BitLocker states, operating-system drives, and data drives so that the sequence can be reconstructed accurately.

Drive letters are not assumed to represent permanent physical disk identities because Windows drive-letter assignments can change between operating-system installations and configurations.


Recovery Keys and BitLocker Protectors

At least one affected volume showed a Numerical Password protector.

An External Key protector was also documented.

Automatic unlock had been enabled on at least one affected volume.

Recovery-key information had been backed up or associated with the Microsoft account.

This distinction is important.

The incident cannot be accurately summarized simply as "the user lost the BitLocker key."

The investigation documented situations where BitLocker volumes could be unlocked but Windows still could not normally access the filesystem.

One resulting Windows error was:

"The disk structure is corrupted and unreadable."

Possession of the encryption credentials and successful BitLocker unlocking therefore did not necessarily restore access to the underlying files.


What the Evidence Currently Establishes

The following points are based on observations, preserved command output, system information, or the sequence of events documented during the investigation.

The computer previously operated under Windows 10.

Windows 11 was subsequently installed on another system SSD.

Multiple existing data drives were connected during the Windows 11 period.

BitLocker encryption became active on multiple data drives.

I did not knowingly initiate that multi-drive encryption process.

Multiple affected volumes subsequently showed incomplete BitLocker conversion.

One documented affected volume was 40.5% encrypted.

Another documented affected volume was 48.0% encrypted.

Both were documented with an "Encryption Paused" conversion state.

XTS-AES 128 encryption was documented.

At least one affected drive contained a Numerical Password recovery protector and an External Key protector.

Automatic unlock was documented on at least one affected volume.

I subsequently returned to Windows 10.

Multiple data drives subsequently became inaccessible or presented serious filesystem/disk errors.

At least one affected unlocked volume produced the Windows error "The disk structure is corrupted and unreadable."

The existence of a BitLocker recovery key did not by itself restore normal filesystem access.

Technical evidence from the incident has been preserved for continued investigation.


What Has Not Yet Been Established

This archive does not claim that every part of the low-level failure mechanism has been conclusively established.

The following questions require further technical investigation:

The precise Windows component or process that initially triggered encryption on each affected data drive.

The precise time encryption began on each volume.

The precise notification or consent workflow presented by Windows 11.

Whether switching from the Microsoft account to a local account affected the conversion process.

Exactly why BitLocker conversion entered a paused state.

Exactly what Windows 10 did when encountering the partially converted volumes.

Whether the filesystem corruption occurred before, during, or after the operating-system transition.

The precise low-level relationship between incomplete BitLocker conversion and the filesystem structures that later became unreadable.

Whether additional Windows event logs or BitLocker metadata can reconstruct the sequence more precisely.

These unresolved questions are intentionally identified as unresolved.

The existence of unanswered technical questions does not change the recorded BitLocker conversion percentages, paused states, operating-system transition, or subsequent accessibility problems.


Why User Awareness Matters

The key practical issue is straightforward.

A user making decisions about operating systems, hardware, backups, account configuration, or disk migration needs to know when an encryption process is actively modifying storage containing important data.

Had I known that multiple data drives were undergoing BitLocker encryption, my behavior would have been different.

I would not have treated the drives as ordinary unchanged storage.

I would have waited.

I would have verified that encryption had completed.

I would have verified recovery information.

I would have made additional backups before changing the operating-system environment.

I would not knowingly have changed operating systems while multiple storage volumes were in incomplete encryption states.

This is why the visibility and communication of active encryption are central issues in this case.


Data Loss and Impact

The affected storage contained substantial professional and personal data accumulated over years.

My professional work involves Unreal Engine development, interactive design, technical art, architectural visualization, 3D design, real-time rendering, virtual reality, digital assets, project files, and related creative and technical material.

Loss of normal access to this storage has therefore had consequences beyond the inconvenience of reinstalling Windows.

The incident has required substantial time for:

Technical investigation

Drive-state documentation

BitLocker analysis

Recovery-key verification

Windows log examination

Disk identification

Recovery research

Drive preservation

Disk imaging and cloning

Data-recovery attempts

Documentation of the incident

Research into similar BitLocker and Windows incidents

The full amount of recoverable and unrecoverable data is still being determined.


Data Recovery and Evidence Preservation

Once the severity of the problem became apparent, the priority shifted toward preserving the original storage and avoiding unnecessary writes.

The recovery investigation has included or considered:

BitLocker status examination

Recovery-key verification

BitLocker protector examination

Physical-disk identification

Windows filesystem errors

Windows event and servicing logs

Disk imaging

Disk cloning

Clonezilla

Recovery software

Read-only examination where practical

Preservation of command output

Preservation of screenshots

Preservation of drive-state information

The objective is to recover as much data as possible while also preserving evidence capable of explaining what occurred.


Windows 11, BitLocker and Device Encryption Research

This case also raises broader questions concerning how Windows 11 communicates storage encryption to users.

Relevant topics include:

Windows 11 BitLocker

Windows 11 Device Encryption

automatic BitLocker encryption

automatic device encryption

BitLocker encryption without explicit user initiation

Microsoft account BitLocker recovery keys

BitLocker recovery-key backup

BitLocker encryption of data drives

BitLocker encryption paused

partially encrypted BitLocker volumes

BitLocker conversion status

BitLocker XTS-AES 128

Windows 11 to Windows 10 downgrade

Windows 10 access to BitLocker volumes

BitLocker filesystem corruption

BitLocker disk structure corrupted and unreadable

BitLocker data recovery

BitLocker multi-drive encryption

unexpected BitLocker encryption

Windows update data loss

Windows 11 storage encryption

Windows 11 encryption transparency

BitLocker user notification

BitLocker user consent

These terms are included because they accurately describe areas relevant to the investigation and may assist researchers and other affected users in locating this case.


Similar Incidents

I am interested in hearing from other Windows users who have experienced similar circumstances, including:

BitLocker unexpectedly becoming active after installing Windows 11.

Multiple data drives being encrypted without the user intentionally starting encryption.

BitLocker encryption being discovered only after an operating-system or hardware change.

BitLocker volumes remaining partially encrypted.

BitLocker reporting "Encryption Paused."

A Windows 11 to Windows 10 transition followed by inaccessible drives.

A BitLocker volume successfully unlocking but subsequently reporting filesystem corruption.

"The disk structure is corrupted and unreadable" after BitLocker unlocking.

Recovery keys working while the underlying filesystem remains inaccessible.

Multiple storage drives becoming inaccessible during the same Windows or BitLocker incident.

Users discovering BitLocker recovery keys in their Microsoft account despite not remembering intentionally enabling BitLocker.

Technical reports, logs, screenshots, recovery results, and reproducible examples are particularly useful.


Request for Independent Technical Analysis

I am seeking technically rigorous analysis of the evidence.

Relevant expertise may include:

Microsoft Windows storage architecture

BitLocker

Full-volume encryption

Windows Device Encryption

NTFS

Storage drivers

BitLocker metadata

Windows event logging

Windows 10 and Windows 11 interoperability

Filesystem recovery

Digital forensics

Data recovery

Storage-device imaging

The goal is to establish the most accurate technical explanation possible.

Evidence contradicting any current assumption is also relevant.

The purpose of this archive is to document what happened accurately, not to substitute an assumption for a technical finding.


Request for Legal and Research Information

I am also interested in information concerning similar documented cases involving Windows, BitLocker, unexpected encryption, inaccessible data, data loss, encryption disclosure, software-update transitions, and storage corruption.

Relevant material may include:

Technical reports

Published research

Microsoft documentation

Microsoft support cases

Consumer complaints

Court cases

Canadian legal proceedings

Class actions

Regulatory findings

Journalistic investigations

Documented cases involving similar technical circumstances

This incident occurred in Canada, and information concerning Canadian cases or affected Canadian Windows users is particularly relevant.


Evidence Archive

The evidence associated with this case includes command-line output, BitLocker status information, drive information, screenshots, logs, recovery information, operating-system observations, and recovery records.

Additional evidence will be published as it is organized and reviewed.

Future supporting posts may contain:

Complete incident timeline

Raw BitLocker command output

Individual drive records

Windows logs

Screenshots

Physical disk information

Recovery attempts

Data-recovery results

Microsoft documentation

Technical analysis

Similar user reports

Legal and consumer research

Updates to the investigation

This master page should be treated as the primary index for the Gerald DesRochers Windows 11 BitLocker data-loss case.


Corrections and Evidence Standards

Accuracy is important.

This page distinguishes among:

Observed events

Recorded technical evidence

My direct recollection

Technical interpretation

Unresolved questions

Third-party reports

Any future correction supported by stronger evidence will be incorporated into the record.

If a technical conclusion cannot currently be demonstrated, it will be identified as an interpretation or unresolved question rather than presented as proven fact.


Contact

My name is Gerald DesRochers.

I am based in Vancouver, British Columbia, Canada.

I am seeking contact with:

People who experienced similar Windows 11 or BitLocker incidents

BitLocker specialists

Windows storage specialists

Digital-forensics experts

Data-recovery specialists

Researchers

Journalists

Consumer-protection researchers

Canadian legal professionals

Law firms investigating technology-related data loss

Microsoft representatives

Anyone possessing relevant technical evidence

If you experienced a similar incident, useful information includes:

Windows version

Approximate date of the incident

Whether Windows 11 had recently been installed

Whether you used a Microsoft account

Whether you later switched to a local account

Number of affected drives

Whether the drives were OS or data drives

BitLocker percentage encrypted

BitLocker conversion status

Encryption method

Protection status

Whether recovery keys existed

Whether the drives unlocked

Exact Windows error messages

Whether filesystem corruption occurred

Whether the data was ultimately recovered

Relevant screenshots or command output


Case Identification

Case subject:

Gerald DesRochers Windows 11 BitLocker Multi-Drive Data Loss Case

Location:

Vancouver, British Columbia, Canada

Primary technologies involved:

Microsoft Windows 11

Microsoft Windows 10

Microsoft BitLocker Drive Encryption

Windows Device Encryption

NTFS and Windows storage

Primary documented symptoms:

Unexpected BitLocker encryption activity

Multiple partially encrypted data drives

BitLocker Encryption Paused

40.5% encrypted volume

48.0% encrypted volume

XTS-AES 128

Windows 11 to Windows 10 operating-system transition

Inaccessible data drives

BitLocker volumes capable of unlocking but not providing normal filesystem access

"The disk structure is corrupted and unreadable"

Multi-drive data loss

Ongoing data-recovery and technical investigation


Current Status

The case remains under technical investigation and data recovery is ongoing.

This page will be updated as additional evidence is organized, additional data is recovered, or stronger technical conclusions become possible.

The core documented issue remains:

Multiple data drives underwent BitLocker encryption during the Windows 11 period without my knowingly initiating the process. Multiple drives were subsequently documented in incomplete encryption states. Following the return to Windows 10, serious drive-access and filesystem problems were encountered.

Had Windows 11 clearly informed me that BitLocker encryption was actively modifying my data drives, I would have allowed that process to complete before changing operating systems.

I was never knowingly given that choice.

Gerald DesRochers
Vancouver, British Columbia, Canada


Comments