Data Recovery Case File · Second Fixes & Trade Handoffs · Verify Each Hop
A Transfer That Reports Success Has Not Reported That Everything Arrived
Her enquiry describes a careful process that failed quietly at its last step. Files transferred to one drive and then onto another, where "something went wrong and the second drive did not transfer all files", the original "now appears to be running but won't connect", and — the detail that identifies the fault — "all email messages in my files have nothing in the body of them." Hollow emails are a signature, and they say precisely which part of the copy failed.
| Media | Original hard drive not connecting to the host, and a second drive holding an incomplete transfer — mail records present with message bodies absent |
| Reported situation | Files transferred from an original drive to a second drive · content subsequently transferred onward to a third · second transfer found to be incomplete · original drive powering but not connecting to the host · mail messages present in the copied set · message bodies absent from those records · recovery sought |
| Fault class | Incomplete copy with linked content omitted — mail stores separating index from message bodies; original drive not presenting, with condition unestablished |
| Equipment used | Hollow mail records interpreted as evidence of which components were omitted · original drive addressed directly with imposed timeouts rather than through the host · imaged write-blocked under strict per-sector timeouts · mail store components located and recovered together rather than individually · copied set reconciled against the original to identify omissions |
The decode: what empty message bodies reveal, and why copies fail silently
Why an email can exist without its content: mail is stored in parts. Many mail applications keep an index of messages — senders, subjects, dates — separately from the bodies, which live in another file or a set of them.
What that means for a copy: the parts must travel together. Copying the index without the store produces exactly what she describes: messages that list correctly and open empty.
Why that particular omission happens so often: the store is hidden. Mail data usually sits in an application folder that is not visible in ordinary browsing, so a copy made by selecting visible folders misses it.
Why it is diagnostic beyond the emails themselves: it identifies the copy method. An omission of hidden application data means the transfer selected visible content rather than duplicating everything.
What that predicts about the rest: other hidden material is missing too. Application settings, licences, browser data and other stores live in the same hidden areas.
Why copies fail without saying so: reporting is partial. A copy operation that skips a file it cannot access frequently continues and reports completion, with the skipped items listed only in a log nobody reads.
Why the two-stage transfer compounded it: each stage could drop something. An omission at the first stage is invisible at the second, which faithfully copies what it was given.
Why the original drive is now the important one: it holds everything. Whatever both transfers missed exists only there.
Why its condition is unestablished rather than bad: running and not connecting covers several faults. A drive that spins and does not present may have an interface fault, a board fault or an initialisation failure, distinguished by measurement.
What the lesson is, stated once: verify each hop before trusting it. A transfer is not complete because it finished — it is complete when something has been read back out of the destination.
On the bench
Hollow mail records were interpreted as evidence of which components were omitted — mail applications commonly separating a message index from the bodies, held in another file or set, so copying the index alone produces messages that list correctly and open empty. Mail stores residing in hidden application folders means a transfer selecting visible content misses them, predicting that settings, licences and other application data are likewise absent. Store components were recovered together.
The outcome
Hollow records read as evidence of omission, the original drive addressed directly rather than through the host, and mail store components recovered together. Free assessment, one fixed written figure including VAT, charged per drive, with 50% of parts and labour upfront where a drive has to be opened. The decode: empty emails identify the fault precisely. Mail keeps its index separately from its bodies, and yours travelled without them — which means other hidden application data did not travel either.
After a transfer that finished but missed things
Keep the original drive and don't clear it — whatever both transfers missed exists only there. Read the empty emails as a diagnosis rather than a curiosity: mail applications keep the message index separately from the bodies, usually in a hidden application folder, so a copy that selected visible content took the index and left the rest. Expect settings, licences and browser data to be missing on the same basis. In future, verify each hop by reading something back out.
Keep the original — call Cambridge Data Recovery on 01223 655015; omissions identified from what came through hollow, original addressed directly, mail store components recovered together.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.