Data Recovery Case File · Mac & Apple Systems · A Baseline Is the Observation
Knowing What Recovery Usually Looks Like Is What Makes This Time Different
His enquiry contains a comparison rather than a symptom. A 4TB drive appearing in the disk utility but greyed out after he force-restarted a crashed machine with it connected, where "normally when this happens it reappears after a while — but I left it attached for two hours, then three, to no avail." The useful observation is the baseline: he knows the normal behaviour, so the departure from it is a measurement rather than an impression.
| Media | 4TB external hard drive with approximately 1TB in use — enumerating and presented as unmounted following a forced host restart; not mounting after several hours |
| Reported situation | External drive connected during a host crash · host restarted forcibly with the drive attached · drive appearing in the disk utility in an unmounted state · drive normally remounting after a period following such events · drive not remounting after two hours and then three · approximately 1TB in use of 4TB capacity |
| Fault class | Volume failing to mount after an unclean dismount — structural inconsistency beyond automatic reconciliation; device enumerating normally |
| Equipment used | Owner's baseline treated as establishing that automatic reconciliation had failed · no repair or check permitted from the host · imaged write-blocked at the block level before any interpretation · filesystem structures interpreted with their duplicate copies · occupied regions prioritised in the capture |
The decode: what usually happens, and what it means that it has not
What the system normally does after an unclean dismount: checks and repairs. A volume that was not properly unmounted is flagged, and the system reconciles its structures before presenting it — which takes time proportional to the volume.
Why that is what he has seen before: the delay is the reconciliation. A drive reappearing after a while is one whose automatic repair completed successfully, and the wait is the work being done.
What it means that three hours produced nothing: the reconciliation did not complete. Either it is failing repeatedly, or it has found inconsistencies it will not resolve automatically, and either way the automatic route has been exhausted.
Why his baseline is the valuable part: without it, three hours means nothing. Someone who had never seen the normal behaviour would not know whether to keep waiting, and might wait indefinitely or intervene far too early.
Why greyed out is a specific state worth reading: the device is present and its volume is not mounted. The utility lists it because the hardware enumerated, and shows it inactive because the filesystem was not accepted.
What that eliminates: the hardware. A drive that enumerates and reports its capacity has passed every stage a mechanical or board fault would have stopped.
What caused it: the forced restart. A machine stopped abruptly with a drive attached leaves whatever was in progress unfinished, including any structural update the filesystem was performing.
Why the offered repair should nonetheless be declined: the utility will offer to fix it. A repair on structures it has already failed to reconcile automatically discards references it cannot verify, which is how folders disappear.
Why his occupancy figure helps: a quarter of the drive is in use. The capture can be aimed at occupied regions rather than four terabytes of mostly empty surface, which is faster and less demanding.
What must not happen now: no further mount attempts, no repair, and no reformatting. Each automatic attempt writes to the structures being reconstructed, and he has already established that they will not resolve on their own.
On the bench
The owner's baseline was treated as establishing that automatic reconciliation had failed — systems flagging volumes that were not cleanly unmounted and reconciling their structures before presentation, a process taking time proportional to the volume, so a drive normally reappearing after a delay is one whose automatic repair completed. Failure across several hours indicates inconsistencies beyond automatic resolution. Enumeration excludes mechanical and board causes. Occupied regions were prioritised in the capture.
The outcome
The baseline treated as establishing that automatic repair had failed, no repair permitted from the host, and structures interpreted with their duplicate copies. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: knowing the normal behaviour is what makes three hours meaningful. The delay you usually see is the system repairing the volume — so its not finishing means the automatic route has run out.
A drive that usually remounts and this time has not
Stop attempting to mount it and decline the repair the utility offers — you've already established that automatic reconciliation won't resolve this, and a manual repair on those same structures discards references it can't verify. Your comparison is the useful part: the delay you normally see after a crash is the system checking and repairing a volume that wasn't cleanly unmounted, so three hours without it finishing means the inconsistencies are beyond that. Being listed but greyed out also rules out hardware faults entirely.
Decline the repair — call Cambridge Data Recovery on 01223 655015; your baseline treated as establishing automatic repair has failed, imaged before interpretation, structures rebuilt from duplicate copies.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.