The call came from a woman in her late fifties. Her husband had died of a sudden cardiac event three weeks earlier, and she was trying to recover the last videos he had taken of their grandchildren. A birthday party, a backyard barbecue, an ordinary Tuesday that turned out to be his last.
His iPhone 14 was locked and she did not know the passcode. He had never set up Family Sharing, never turned on iCloud Photos, never named a Legacy Contact in Apple's settings. She had tried the dates that mattered to him, birthdays and their anniversary and the year they moved to Canada, and gotten nowhere. On her twelfth attempt the phone disabled itself.
This is one of the most common cases we receive, and one of the most misunderstood.
What most people believe
There is a persistent idea, reinforced by crime dramas and tech news headlines, that a forensics lab can simply crack a locked iPhone. Hand it over, wait a few days, get the data back.
The reality is more complicated. Modern iPhones are, by design, among the most difficult storage devices in the world to extract data from without the owner's cooperation. Apple built them that way deliberately and the security is real.
Understanding what a lab can actually do means first understanding what is standing in the way.
The lock is not just software
Setting a passcode on an iPhone does more than create a login screen. It triggers a hardware encryption system built into the chip itself.
Every iPhone since the 5s contains a dedicated security processor called the Secure Enclave, whose only job is to manage cryptographic keys. The key that decrypts your data is derived from two things: a hardware identifier burned into the chip at the factory, and your passcode. The Secure Enclave holds one half and your passcode supplies the other.
So the data on the device is encrypted at rest. Without both halves of the key, the contents of the flash storage are unreadable, just random-looking bytes. And because one half of the key never leaves the chip, decryption cannot happen anywhere else. You cannot pull the storage chip, attach it to another machine and read the contents. You cannot clone the device and brute-force it in parallel. Decryption has to happen on that specific phone.
The Secure Enclave also enforces attempt limits. After six wrong passcode attempts the phone imposes mandatory wait times: one minute, then five, then fifteen, then sixty. If the owner had enabled "Erase Data After 10 Attempts," the phone wipes itself on the tenth failure. If not, it will keep enforcing delays indefinitely.
On an iPhone with a six-digit numeric passcode there are one million possible combinations. At sixty-second intervals, methodically trying every one would take well over a year, assuming the phone never erased itself and assuming you could somehow automate the attempts, which the Secure Enclave is specifically designed to prevent.
None of that is a weakness in Apple's implementation. It is the implementation working as intended.
What "brute force" actually means in a lab
When forensics professionals talk about brute-forcing a locked iPhone, they are not describing someone typing passcodes by hand. They mean specialized hardware, purpose-built devices that connect to the iPhone and try to interact with the Secure Enclave at a lower level than the normal software interface allows.
The two significant tools in this space are Cellebrite Premium and GrayKey, developed by Grayshift. Both are enterprise-grade, law enforcement-oriented tools that cost tens of thousands of dollars and are sold only to vetted agencies and certified forensics firms.
They work by exploiting implementation-level vulnerabilities in the Secure Enclave's boot process or in iOS itself, and Apple patches those vulnerabilities with each major iOS release. So their effectiveness is tied directly to the iOS version running on the device and to the chip generation.
The picture as of mid-2026:
- iPhone 15 and later (A16/A17 chip), iOS 17+: no publicly known extraction path via brute force. These devices are considered forensically inaccessible without the passcode.
- iPhone 12–14 (A14/A15 chip), iOS 16–17: limited extraction possible on some configurations. Not guaranteed, and heavily dependent on the specific iOS build.
- iPhone X–11 (A11–A13 chip), older iOS: more tractable, particularly on an older iOS version that has not been patched.
- iPhone 8 and earlier: generally accessible with current professional tools, particularly with 4-digit PINs.
The woman who called us had her husband's iPhone 14 running iOS 17. That is the hardest category we work with.
BFU vs AFU: the state of the device matters enormously
One of the most important variables, and one families rarely know about, is whether the phone has been unlocked since its last reboot.
When an iPhone is first powered on, or immediately after a restart, it sits in a state called BFU, Before First Unlock. In that state the vast majority of the device's data stays fully encrypted. Even if a forensic tool successfully bypasses the passcode, it can only see a fraction of the content: basic metadata, some system files, certain low-security app data.
Once the owner enters their passcode at least once after a reboot, the phone moves to AFU, After First Unlock, where the encryption keys for most user data are held in memory. Extraction becomes dramatically more useful. A device received in AFU state and kept powered on yields far richer results.
Most phones that arrive from grieving families have been sitting on a charger for days or weeks. They may have auto-restarted for a software update, or been intentionally rebooted while family members tried various passcode combinations. A device in BFU state limits what even a successful extraction can reach.
The husband's iPhone 14 had been powered on and off several times since his death. It was firmly in BFU. Whatever extraction path existed would reach only a portion of the data.
The path we recommend first
Before any forensic tool enters the conversation, every case involving a deceased person should start with Apple's Digital Legacy program.
Apple introduced Digital Legacy in iOS 15.2. It lets iPhone owners designate specific people, Legacy Contacts, who can request access to their iCloud account after death. With a death certificate and the access key generated when the Legacy Contact was set up, Apple will transfer the iCloud data to the surviving contact within a few weeks.
Where no Legacy Contact was set up, as here, family members can still apply directly to Apple with a death certificate and proof of relationship. Apple reviews these requests and in many cases will provide access to the iCloud account, including iCloud Photos, iCloud Drive, Notes and Messages if iCloud Messages was enabled.
This process does not unlock the physical device. But if the deceased person had iCloud backups or iCloud Photos turned on, it may deliver exactly what the family is looking for with no forensic work at all.
In this case the husband had iCloud Photos enabled, though he had not used iCloud for backups. Apple's Digital Legacy process gave his wife access to 4,200 photographs, including the birthday party, the barbecue, and the Tuesday that turned out to be his last. The videos she was looking for were in there.
For her purposes, the physical phone turned out to be irrelevant.
When Apple's process isn't enough
Digital Legacy covers iCloud data. It does not cover what exists only on the physical device: notes that never synced, messages in apps without cloud backup, voice memos, locally saved files, data from apps that do not connect to iCloud at all.
For families where the irreplaceable content is on the device and nowhere else, a forensic examination of the physical phone may be the only route left.
The realistic outcomes depend on the variables above, meaning device model, iOS version, device state and passcode type. We assess all of them before making any commitment to a client about what is achievable.
Where extraction is possible, we perform a full logical or physical extraction using professional tools, document our methodology, and return the data in a format the family can actually use. Organized, readable files, not a raw evidence package.
Where the device is forensically inaccessible, meaning an iPhone 15 on current iOS, or a device in BFU with no known extraction path, we say so clearly before any invoice is issued. We would rather disappoint a family early than take their money for work that cannot succeed.
A note on legality
Accessing another person's device without authorization is a criminal offence in Canada under the Criminal Code and the PIPEDA framework. The death of the owner does not automatically transfer access rights.
The parties who can authorize forensic access to a deceased person's device are the estate executor named in the will, the next of kin, or a court. We require documentation confirming authorization before beginning any examination. Not as a procedural formality, but because chain of custody matters if the data is ever needed in an estate dispute, a legal proceeding or a coroner's inquiry.
What to do if you're in this situation
If you have a loved one's locked iPhone and need to get into it:
- Stop guessing the passcode. Every failed attempt burns one of a limited number of tries and risks triggering the erase function. Stop at five or six and call a professional.
- Keep the device charged and powered on. Do not restart it. AFU state preserves more recoverable data than BFU.
- Contact Apple first. Apply for Digital Legacy access with a death certificate. Even if you do not think the data is in iCloud, check anyway, because plenty of people have cloud backup enabled without knowing it.
- If Apple's process doesn't cover what you need, speak to a forensics lab before writing the phone off. Outcomes vary enormously with the specific device and software version.
The phone sitting in your drawer may be accessible and it may not be. Answering that honestly requires looking at the specific device.
We work with families, estate lawyers, and administrators on next-of-kin device access. Every case starts with a scoped consultation before any work begins. Contact us to discuss your situation.