Call us — 01223 655015
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Solid State & Flash · The Label Is the Evidence

A Volume Name Reverting to a Default Means the Filesystem Was Replaced

Her enquiry contains an observation that most people would mention only in passing, and it is the strongest evidence in the case. A stick where "everything from the past few years had disappeared", and which "had also changed its name to a default label, whilst before it was named something else." A volume does not rename itself: the name is stored inside the filesystem, so a new name means a new filesystem was written where the old one used to be.

MediaUSB flash drive holding several years of academic and professional work — content absent; volume label reverted to a system default from a previously assigned name
Reported situationFlash drive in regular use over several years · content from the recent period no longer present · volume label observed to have changed to a generic default · previous label having been a name assigned by the owner · academic and work material sought
Fault classFilesystem replaced rather than damaged — new structures written over the volume descriptor; prior content regions substantially retained and unreferenced
Equipment usedLabel change interpreted as filesystem replacement rather than as corruption · device removed from use before any examination · imaged write-blocked at the block level before any interpretation · prior filesystem structures recovered from residual copies beyond the replaced descriptor · content carved by signature and reconciled against recovered directory records

The decode: why a name cannot change on its own

Where a volume's name is actually stored: inside the filesystem. The label sits in the structure that describes the volume, written when the filesystem was created or when the name was set.

Why that makes the change so informative: nothing else can alter it. A device cannot rename itself, and damage does not substitute a valid default name for a valid custom one.

What must therefore have happened: a new filesystem was written. Creating one writes a fresh descriptor, and where no name is supplied, a default appears.

Why that is a different fault from the one she assumed: she reports things disappearing. This is not degradation or corruption but a replacement, which behaves quite differently.

Why it matters that the difference is favourable: replacement writes very little. Creating a filesystem writes a descriptor and empty structures, occupying a small fraction of the device.

What that means for the content: it is still there. The years of work were never written over — they are simply no longer described by anything.

Why the old files can be found without the old description: they have their own structure. Documents carry recognisable openings, and the previous filesystem's records frequently survive outside the replaced region.

What could have caused a filesystem to be replaced without her asking: several ordinary things. An accepted prompt to format, a repair tool, a device configuring itself, or a system offering to make an unreadable volume usable.

Why identifying which hardly matters now: the effect is the same. What determines the outcome is how much has been written since, not what did the writing.

What must happen immediately: the stick stays out. The new filesystem regards the entire device as empty, so anything saved to it now lands directly on the old content.

On the bench

The label change was interpreted as filesystem replacement rather than as corruption — a volume's name being stored within the structure describing it, so a device cannot rename itself and damage does not substitute a valid default for a valid custom name, leaving creation of a new filesystem as the explanation. That writes only a descriptor and empty structures, occupying a small fraction of the device. Prior structures were recovered from residual copies beyond the replaced descriptor.

The outcome

The label change read as filesystem replacement, the device removed from use, and prior structures recovered from residual copies. Free assessment, one fixed written figure including VAT; on flash devices where content has been deleted or overwritten, the figure is payable upfront. The decode: noticing the name is what solves this. A volume cannot rename itself — the label lives inside the filesystem, so a default name means a new filesystem was written where the old one was.

A drive that has acquired a different name

Stop using it entirely — the new filesystem regards the whole device as empty, so anything saved to it now lands directly on top of what you're trying to recover. Mention the name change, because it's the most useful thing you've noticed: a volume's label is stored inside the structure describing it, so a device can't rename itself and corruption doesn't swap a custom name for a valid default. That means a filesystem was created, which writes very little and leaves your content in place.

Drive renamed itself and lost everything?
Stop using it — call Cambridge Data Recovery on 01223 655015; the label read as filesystem replacement, imaged write-blocked, prior structures recovered from residual copies.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.