Data from a Dead MacBook: What Can and Cannot Be Recovered

Quick answer

Whether data can be recovered from a dead MacBook is determined not by the extent of the damage, but by the generation of the machine. On Intel models up to around 2017, the storage is a separate component and, unless FileVault was enabled, it can usually be read elsewhere. On models with the T2 chip (2018–2020) and all models with Apple silicon (M1 and newer), the internal drive is always encrypted and its keys reside in the Secure Enclave of that specific machine. If the logic board dies, the data cannot be read anywhere else, so the only route to recovery is to revive the board at least partially. If your MacBook still starts, stop thinking about repairs and back it up now; it is the cheapest form of data recovery there is.

This article covers situations where no backup exists. If you have a backup but it is not working, that is a different issue—the article MacBook data recovery: Time Machine, FileVault, and soldered SSDs discusses backup recovery and damaged Time Machine archives. Here, the focus is on the correct order of steps and a realistic assessment of your chances when the computer contains the only copy.

First question: does the machine still start?

This would sound trivial if not for one crucial fact: the difference between „starts„ and „does not start" represents the largest gap in both cost and recovery prospects in this field. If the MacBook reaches the login screen, the data is essentially yours and only needs to be copied elsewhere. If it does not, work on the logic board begins.

That leads to some uncomfortable but honest advice: if the computer is working right now and you are reading this article because it has „been acting up lately," stop reading and make a backup. Shutting down during use, random restarts, fans running at full speed, intermittent black screens, or failure to boot after an update are common warning signs of logic board failure in Macs. Once the board finally fails, there will be no time left to create a backup.

One more check costs nothing: sign in to iCloud from another device and see what is actually stored there. Many people have their Desktop and Documents folders synchronized without realizing it—and the file they need may already be outside the computer.

The generational divide determines everything

In 2018, Apple changed the design in a way that also changed the very nature of data recovery. The decisive issue is not so much that the storage is soldered in, but that it is encrypted from the outset and tied to a specific piece of silicon.

GenerationExample models (Apple identifier)What it means for your data
Intel without T2, roughly up to 2017MacBook Pro (Retina, 13″/15″, 2012–2015) — MacBookPro10,2, MacBookPro11,1, MacBookPro12,1, MacBookPro11,4; MacBook Pro 2016–2017 — MacBookPro13,x and MacBookPro14,x; MacBook Air 2010–2017 — MacBookAir3,1 through MacBookAir7,2The storage is a separate component. If FileVault was not enabled, its contents can also be read outside the original computer—the recovery options depend on the condition of the storage medium itself.
Intel with the T2 chip, 2018–2020MacBook Pro (2018–2020) — MacBookPro15,x and MacBookPro16,x; MacBook Air (Retina, 2018–2020) — MacBookAir8,1, MacBookAir8,2, MacBookAir9,1The contents are always encrypted. The key is tied to the Secure Enclave on that logic board; storage removed from the machine is unreadable in another computer.
Apple silicon, since late 2020MacBook Pro 13″ M1 (2020) — MacBookPro17,1; MacBook Pro 14″/16″ 2021 — MacBookPro18,3, MacBookPro18,4, MacBookPro18,1, MacBookPro18,2; MacBook Air M1 (2020) — MacBookAir10,1; MacBook Air M2 (2022) — Mac14,2; MacBook Air M3 (2024) — Mac15,12, Mac15,13; MacBook Air M4 (2025) — Mac16,12, Mac16,13The same applies as with T2, only more comprehensively. The data lives and dies with the logic board; laboratory recovery requires repairing that board.

The table does not guarantee an outcome for any particular machine. Its purpose is to ensure that you do not submit an enquiry saying only „my MacBook does not work," but include its generation—because that determines whether the job involves the storage medium or the logic board.

You can find the model identifier (for example, MacBookPro14,1) in System Information on a working Mac, and Apple lists it for every model on its identification pages. If the machine will not start, use the marking on the underside of the chassis; how to identify the exact Apple device model before requesting service explains how to read it.

What „always encrypted" means

This often comes as the biggest surprise to owners because they never knowingly enabled FileVault. According to Apple, however, every APFS volume is created with a volume encryption key. If you do not enable FileVault during the Mac’s initial setup, the volume is still encrypted, but its key is protected only by the hardware UID in the Secure Enclave.

The practical consequences can be summarized in three points:

  • On Macs with Apple silicon and the T2 chip, all key operations take place inside the Secure Enclave, and the keys are never exposed to the processor. They are not stored anywhere on the drive in a readable form that could be extracted.
  • Without valid login credentials or a recovery key, internal APFS volumes remain encrypted, even if the storage is physically removed and connected to another computer. This is not a limitation of any particular laboratory; it is an intentional part of the design.
  • The key hierarchy is specifically designed to prevent the storage from being read outside the Mac—one of its stated objectives is to prevent brute-force attacks on storage removed from the computer.

This answers the most common question: transferring the memory chips to another logic board does not work because the other board’s Secure Enclave does not know the original machine’s keys. The article about Time Machine and soldered SSDs explains in detail why desoldering the chips does not work either.

FileVault adds another lock

Automatic encryption and enabled FileVault are not the same thing. When you enable FileVault, the key is additionally protected by a combination of your password and the hardware UID, and the password is required during startup. This creates a second barrier that also applies to you:

  • Without the password or recovery key, the data cannot be decrypted. The recovery key is a 24-character sequence generated by macOS when FileVault is enabled.
  • The key may be stored in Keychain and synchronized through iCloud Keychain—if you configured it that way, it is worth checking Passwords on another device before giving up.
  • In a company, device management may hold the key. For a work MacBook, your first call should be to IT, not a repair shop.

The opposite applies to older Intel models without T2: if FileVault was not enabled, encryption does not apply and the data can be read normally. That is precisely why their storage can be handled separately.

While the machine still starts: how to get the data out

There are three options, listed in the order in which they most commonly work:

  1. A Time Machine backup to an external drive. Even a one-off backup started this evening is better than a plan to begin backing up regularly. If the MacBook still boots, this is the fastest and most complete solution.
  2. Disk Sharing (Mac with Apple silicon). Start the Mac in macOS Recovery, choose Utilities → Share Disk, select the volume, and click Start Sharing. Connect the two computers using a USB, USB-C, or Thunderbolt cable. On the second Mac, open Finder → Network, double-click the shared Mac, select Connect As → Guest, and transfer the files.
  3. Target Disk Mode (older Intel Mac). This is the equivalent option for models made before the transition to Apple silicon—the Mac is connected to another computer by cable and mounted as an external drive.

Disk Sharing has one condition that should not be overlooked: if FileVault is enabled, you will still need the password. Without it, the volume will not mount even if the machine otherwise starts.

One more warning in the same vein: in Recovery mode, do not erase the volume or blindly reinstall the operating system. Reinstalling „over the data" may be reversible; erasing the volume is not.

When it becomes a job for a laboratory

A MacBook belongs in a laboratory once it no longer starts and further attempts at home would only increase the risk. Typical cases include:

  • After liquid damage. Corrosion continues to affect the logic board even when it is switched off, and progresses faster while power is present. The sooner the board is dismantled and cleaned, the better the prospects.
  • After a fall or power surge when the machine shows no signs of life.
  • After an unsuccessful intervention, whether attempted by you or someone else.
  • When the machine begins to start and immediately shuts down or only starts occasionally—every further attempt could be the last.

What actually happens with a dead Mac: the power rails are measured, the condition of the processor and Secure Enclave is checked, and a way is sought to bring the logic board at least to a state in which it can unlock the volume and allow the data to be read. A functioning chip, not a „good drive," is what matters—and that is also why we do not promise outcomes for MacBooks over the phone.

With older Intel models without T2, by contrast, the storage medium is handled separately and the chances depend on its condition, not on the condition of the computer.

Where our service ends

We recover data from hard drives, SSDs, RAID arrays, and MacBooks in our own laboratory in Brno. We do not recover data from mobile phones—not from iPhones, not from Android devices, and not as an add-on to a repair. If your enquiry concerns a phone, we will tell you immediately rather than keep you waiting.

MacBooks are different: they are a legitimate data recovery job and we accept them. Call 775 556 063 (data recovery line) or write to us through the contact page; the data recovery page explains everything included in our service.

What to prepare before contacting us

  • The entire MacBook and its power adapter—not just a removed component.
  • The exact generation or model identifier, ideally along with the serial number for private verification (it should not be posted in a public listing or sent to a third party by email).
  • The user account password and Apple Account credentials; without them, newer models may not even allow us to unlock the volume.
  • The FileVault recovery key, if you saved it when enabling FileVault.
  • A description of what happened before the failure—a fall, liquid exposure, an update, or an unexpected shutdown. The sequence of events helps diagnosis more than you might expect.
  • A list of what matters most. Success does not mean finding any collection of old files; it means recovering the specific folders you need.

The article how Apple device diagnostics and repair approval work describes the intake, findings, and approval process. For company-owned machines, ownership and device management must also be considered; that topic is covered in business MacBook and iPad service in Brno.

Frequently asked questions

Can data be recovered from a MacBook Air M1 (2020) that will not turn on?

Sometimes, but the drive is not the deciding factor. The storage contents of a MacBook Air M1 (MacBookAir10,1) are encrypted, with the keys held in the Secure Enclave, so recovering the data requires reviving the original logic board. If the processor and its Secure Enclave have survived, there may be a path to the data; if they have not, no technology can make it accessible.

My 2015 13″ MacBook Pro will not boot—can its drive be read in another computer?

On 2012–2015 models (such as MacBookPro12,1), the storage is a separate component and, if FileVault was not enabled, it can usually be read outside the original computer. The chances then depend on the condition of the storage medium itself, not on the condition of the laptop. If FileVault was enabled, you will need the password or recovery key.

I have a 2018 MacBook Pro and never enabled FileVault. Is the data unencrypted?

No. MacBook Pro models from 2018–2020 have the T2 chip, and their APFS volumes are encrypted even without FileVault enabled—the key is simply protected only by the hardware UID in the Secure Enclave. The removed storage is therefore unreadable in another computer either way.

Will you repair the logic board if I only need the data?

That is exactly the question worth asking in advance. In data recovery, the goal is to bring the machine to a state in which it can unlock the volume once and allow its contents to be read—not to make it suitable for continued use. This often involves a different scope of work from a full repair, and you deserve to know exactly what you are ordering.

Can you recover data from my iPhone while you are already working on my MacBook?

No. We do not offer data recovery from mobile phones. For a phone, the only protection for its contents is a backup created while the device is still working.

Sources