Call us — 01223 655015
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Formatted & Logical Faults · Connected Is Not Safe

A Backup Attached During a Risky Operation Is Exposed to That Operation

His enquiry describes a precaution that became part of the problem. A partition being resized overnight with a shutdown scheduled for afterwards, and a backup drive "plugged in from refreshing it in case of any issues" — after which the resized partition will not mount, and, more pressingly, another partition "and a copy of it on the backup drive are now showing as empty." The backup was in the room, and that is the lesson underneath the technical fault.

MediaInternal drive with multiple partitions undergoing a resize, and an external backup drive connected throughout — resized partition not mounting; a second partition and its backup copy both listing as empty
Reported situationPartition resize commenced on a multi-partition internal drive · backup drive connected and recently refreshed · automatic shutdown scheduled for an hour after the expected completion · resized partition not mounting afterwards · a separate partition listing as empty · the corresponding copy on the backup drive also listing as empty · recovery of that second partition sought
Fault classResize interrupted with partition table left inconsistent — content regions substantially retained on both drives; directory structures unreferenced rather than erased
Equipment usedBoth drives treated as affected rather than the backup treated as intact · both removed from use before any examination · each imaged write-blocked at the block level before any interpretation · partition boundaries reconstructed from filesystem signatures rather than from the tables · directory structures recovered from residual copies on each drive independently

The decode: what a resize does, and how a second drive was reached

What resizing a partition physically involves: moving data. Changing where a partition begins or ends requires content to be relocated and the tables describing it rewritten, which is among the most write-intensive operations a drive undergoes.

Why interrupting one is so damaging: the description and the content disagree. An operation stopped partway leaves a table describing an arrangement that only partly exists.

Why the scheduled shutdown is the likely interruption: the estimate was wrong. Resize durations are notoriously hard to predict, and a shutdown timed against an estimate can arrive while the operation is still running.

Why a neighbouring partition was affected: they share a table. All partitions on a drive are described by one structure, so damage to it affects every partition rather than the one being changed.

Why that partition lists as empty rather than missing: its boundaries are wrong. A filesystem read from slightly the wrong starting point produces a volume that mounts and appears to contain nothing.

Why that is the encouraging reading: the content is untouched. An empty listing from a misplaced boundary means the files are exactly where they were and are simply not being found.

Now the backup, which is the part worth dwelling on: it was connected. A drive attached to a machine performing partition operations is a candidate for those operations, and tools address drives by identifiers that can shift when a table is rewritten.

Why that turns a precaution into an exposure: a backup's value is being separate. A copy connected to the same machine during the same operation shares the machine's risks.

Why both drives are nonetheless likely recoverable: the damage is structural on both. Neither had its content regions rewritten, so both are reconstructed the same way.

What must happen now: both drives out of use and no repair attempted on either. The natural instinct is to run a partition tool to fix the table, and that would write over exactly what identifies the original boundaries.

On the bench

Both drives were treated as affected rather than the backup treated as intact — a resize relocating content and rewriting the tables describing it, so interruption leaves a description matching an arrangement that only partly exists. All partitions on a drive share one describing structure, so a neighbouring volume read from a misplaced boundary mounts and appears empty while its content is untouched. Partition boundaries were reconstructed from filesystem signatures rather than from the tables.

The outcome

Both drives treated as affected, both removed from use, and boundaries reconstructed from filesystem signatures. Free assessment, one fixed written figure including VAT, charged per drive; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success. The decode: a partition listing as empty is usually being read from the wrong starting point, which means your files are exactly where they always were. Both drives recover the same way.

Before resizing or repartitioning anything

Disconnect the backup. A copy attached to the machine during the operation shares the machine's risks, and partition tools address drives by identifiers that can shift when tables are rewritten — so the precaution becomes an exposure. Don't schedule a shutdown against an estimate either, since resize durations are notoriously unpredictable. If it has already happened, take both drives out of use and run no partition repair: an empty-looking volume is usually being read from the wrong starting point, and a repair would overwrite what identifies the right one.

Resize interrupted and partitions showing empty?
Unplug both drives — call Cambridge Data Recovery on 01223 655015; both treated as affected, imaged write-blocked, boundaries reconstructed from filesystem signatures rather than the tables.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.