Skip to main content

    Security updates · Originally published 13 May 2026 · Updated 20 May 2026 · 6 min read

    Security bulletin May 2026

    Brief

    An exploit has been released online that can bypass BitLocker protections on all Windows 11 & Server 2025 computers. The exploit can be used to steal company data and inject other exploits onto your computers.

    Background

    BitLocker is a disk encryption system made by Microsoft and included in Windows since Vista.  It scrambles the data on the disk so that it can’t be read unless you have a special code (Key).  One of the key features of this is to protect against theft of company data if a laptop is accidentally left in a public place.  In many business sectors there are also regulatory compliance requirements for this.

    The exploit

    A hacker going by the name of Nightmare-Eclipse released ‘Proof of concept’ code on 12th May 2026.  We have tested this and can confirm that it works as advertised.

    The exploit makes use of the Windows Recovery Environment (WinRE) with some special code on a USB stick to trick the computer’s Trusted Platform Module (TPM) into releasing the decryption Key.  Due to the way the WinRE works, this then gives the hackers SYSTEM (the highest access in Windows) level access to your data which is now un-encrypted.

    Important data can now be copied from your device, other hacking tools could be injected into your device and because of the recovery environment, no logs will be left to show that files were copied or modified.

    The exploit requires physical access to the device, this (at present) cannot be exploited by hackers over the internet.

    This risk of exploitation represents a material breach of GDPR rules.

     

     

    HowTech can help you

    Should you feel that your device may have been compromised as described above, HowTech can help! Get in touch and we can perform security tests to ascertain the integrity of your devices and data on your servers or cloud platforms. If there is any reason to believe that your data has been breached we can identify the extent of the breach and will then assist in the legally required reporting.

    By law this check must be performed and any breach reported to the ICO under GDPR rules within 72 hours of you becoming aware of a breach.

     

    Revision history

    • 20 May 2026 — Added note on Microsoft's partial mitigation; reiterated that the startup PIN protection is expected to be compromised.
    • 13 May 2026 — Original publication.