Data Recovery Case File · Cameras, Drones & Cards · Completed Is Not Verified
A Transfer Reporting Success Is Reporting That It Stopped, Not That Everything Arrived
This enquiry describes a sequence that ends badly through no carelessness at all. Photographs copied from a phone's card to a laptop where "the majority transferred okay, some missing, the earliest ones on the card" — deleted from the card once the transfer reported completion, and the gap noticed only later, with the card still in use since. Completion and verification are different claims, and only one of them was made.
| Media | Phone memory card — partial transfer to a host with the earliest content absent; source deleted following the transfer; card in continued use since |
| Reported situation | Photographs transferred from a phone card to a laptop · majority of content arriving successfully · earliest content found to be absent · card contents deleted after the transfer reported completion · absence noticed some time later · card remaining in use in the interval · recovery of the missing photographs sought |
| Fault class | Incomplete transfer followed by source deletion — earliest regions unread and subsequently unreferenced; continued use determining survival |
| Equipment used | Position of the missing content treated as diagnostic of the read failure · card removed from use as the immediate priority · imaged write-blocked before any scanning · signature carving performed across the whole card independently of directory entries · recovered images validated by opening at full resolution |
The decode: why the earliest ones, and what continued use has cost
What a transfer reports when it finishes: that it stopped. A progress indicator reaching the end means the operation ran to completion, not that every file arrived intact, and files skipped after a read error frequently pass without a visible warning.
Why that distinction is invisible in practice: nothing prompts you to compare. A transfer that copies most of a folder and silently omits some looks identical to one that copied all of it, and the count is rarely checked.
Why the earliest photographs specifically: position is diagnostic. The oldest content sits in the regions written first, which have been in place longest and read least recently — and on flash media those are where charge retention has had the most time to drift.
What that suggests about the mechanism: the early regions could not be read cleanly. The transfer encountered errors there, skipped what it could not obtain, and continued, which is exactly the behaviour of an ordinary copy.
Why deleting the source afterwards was reasonable: the operation said it was done. Acting on that is what the report invites, and the alternative — auditing several hundred files by hand — is not something anybody does.
What deleting actually did: removed the entries. The photographs remained where they were written, unreferenced, exactly as with any deletion.
Why continued use is the real cost: a card in a phone writes constantly. New photographs, application data and cached content all allocate from space the deletion released, and weeks of that is a great deal of writing.
Why the position works against her here too: devices allocate released space readily. The regions holding the earliest images are among the first offered back, being the oldest and longest unreferenced.
What the honest expectation is: partial, and worth attempting. Images are small, they survive in gaps, and a card in ordinary use writes far less than its full capacity — so scattered survivors are realistic while a complete set is not.
What should change afterwards, and it is one habit: compare the counts before deleting anything. Checking that the destination holds as many files as the source is a few seconds and it is the verification a transfer does not perform.
On the bench
The position of the missing content was treated as diagnostic of the read failure — a completed transfer indicating the operation ran to its end rather than that every file arrived, with files skipped after read errors frequently passing without visible warning. Earliest content occupies regions written first and read least recently, where charge retention has drifted longest on flash media. Deletion removes entries while content persists, and continued use allocates from the released space. Carving ran across the whole card independently of directory entries.
The outcome
Position treated as diagnostic, the card removed from use, and carving performed independently of the directory. Free assessment, one fixed written figure including VAT; on cards where content has been deleted or overwritten, the figure is payable upfront. The decode: a completed transfer reports that it stopped, not that everything arrived. The earliest photographs were the hardest to read, so those are what it skipped — and they were still there until the card kept being used.
Before deleting a card after copying it
Compare the file counts between source and destination first — that takes seconds and it's the verification a transfer doesn't perform. A progress bar reaching the end means the operation finished, not that every file arrived, and files skipped after read errors often pass with no visible warning. If it's already happened, take the card out of the device now: deletion only removed the entries, but continued use writes into exactly that space. Note which files are missing, since the oldest are the hardest to read and the first to be reused.
Take it out of the device — call Cambridge Data Recovery on 01223 655015; position treated as diagnostic, imaged before scanning, carving performed independently of the directory.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.