Microsoft’s Windows Recall AI feature hasn’t launched yet but it’s already a target.

Microsoft has been touting its Windows Recall AI feature as a must-have for anyone who wants to remember an old webpage or message. But a new reveal suggests it may also come with its fair share of security problems.
Microsoft unveiled the Windows Recall feature last month, touting it as the next iteration of using artificial intelligence (AI) to remember what you do on a PC. The feature captures a copy of the PC every five seconds and can be queried for information, including messages previously sent, conversations with friends, and even a recipe that users may have accessed a week prior. Microsoft said the feature would save users time and make the experience of using Windows 11 far more efficient.
Microsoft also touted how the captures would be stored on the device, so data wouldn’t be transferred to the cloud, preserving security. Indeed, a Windows 11 machine’s entire hard drive is encrypted when a user isn’t logged into their system account. However, when the user does log in, the entire drive is decrypted, making information — including Recalls — available to the user and readily accessible to bad actors who want to steal the data.
Ethical hacker Alex Hagenah has launched a tool, called TotalRecall, that shows how anyone with enough know-how and the right tools could steal the recalls saved on a Windows machine and access that data, encryption-free, on a target device. According to Hagenah, whose work was reported on earlier by Wired, he analyzed Windows Recall and found that the tool — which takes screen captures of a Windows machine every five seconds — stores the data completely unencrypted on the user’s computer.
“TotalRecall copies the databases and screenshots and then parses the database for potentially interesting artifacts,” Hagenah wrote in a GitHub posting about TotalRecall. “You can define dates to limit the extraction as well as search for strings (that were extracted via Recall OCR) of interest. There is no rocket science behind all this.”

TotalRecall is designed to run on a target PC and automatically locate where Recall snapshots are located. The tool can then set a date range for analyzing data or look at what happened on a person’s computer at a specific time. While it hasn’t been exploited in the wild — Recall AI hasn’t launched yet, after all — it could pave the way for hackers with know-how or even domestic abusers to run a version of TotalRecall on a machine surreptitiously to monitor and steal sensitive information, conversations, emails, and more.
Microsoft initially announced Recall as an on-by-default preview feature on Copilot+ PCs specialized for AI, which was set to become available starting June 18.
However, in response to the backlash, Microsoft announced on June 7 that the feature would be disabled by default. In an update shared on June 13, the tech giant said it has decided not to make Recall available on Copilot+ PCs. Instead, a Recall preview will first become available in the Windows Insider Program (WIP) in the coming weeks, and it will be rolled out to Copilot+ PCs after receiving feedback from the Windows Insider Community.
If you are concerned if it is active, here are the steps to take to ensure its disabled:
- Open Windows Settings(WIN+I)
- Select “Privacy & Security”in the sidebar.
- Select “Recall & Snapshots.”
- Toggle “Save Snapshots” to off.
- Select “Delete Snapshots.”
- Select “Delete All.”
- Close Windows Settings.
Please do not hesitate to reach out to us if you have any questions or concerns!
