In-depth write-ups of real recoveries and investigations — the diagnosis, the tools and exactly how each job was brought back. Most drives are imaged on our PC3000 and DeepSpar systems before any recovery begins. For shorter summaries, see our case studies.
Five SAS drives running a finance business. A spare rebuilt the array four months earlier and was never replaced, so the second failure hit an array with no redundancy left.
A two-bay unit the owner believed was a mirror. It was a stripe, so pulling the screeching disk removed half of every file. Platter swap in clean air.
Windows saw the drive and lit the enclosure, so the owner assumed the disk was alive. The head assembly had failed on impact — detection says nothing about whether the heads can read.
Dropped while running. New heads restored the ability to read, but coating removed from the surface during the fall is not recoverable by any method.
The motor could not break the heads free of the platter surfaces. Released in clean air before repeated power cycling could score the disks.
A seized motor and WD hardware encryption the owner never knew was enabled. Spindle freed, encryption addressed on PC-3000, family photographs delivered by cloud.
Out of service since 2006, showing folder structures slowly and failing on copy. Faulty board replaced with the adaptive ROM transferred, and firmware corrected.
Unrecognised across three machines and two cables. Power reaching the unit and cycling repeatedly — board and firmware faults on a ten-year-old external.
A drive that sounds perfectly healthy and never appears is failing at identification, not rotation. Service area corrected with no mechanical work at all.
Connecting less often each time, with a damaged port. Imaged on DeepSpar hardware — read once and move on, where conventional copying would have finished the drive.
Forty seconds of operation after cooling, then thermal shutdown. With no way to keep the board powered, the NAND was removed from the M.2 module and read directly.
No recovery key available. The volume key was located in the host machine's memory, where the running system had legitimately placed it. Nothing about AES was attacked.
On a 2008 Mac the storage lifts out and the machine's condition is irrelevant. File system damage from a power surge, repaired against the image.
Photographs that were viewable and then vanished. The card's directory structures had failed while the images remained physically present in the flash.
A mirrored pair moved to a new PC and inaccessible. The configuration had reset — and crucially no rebuild followed, which is what kept both copies intact.
Not case studies. Each describes a failure pattern we handle regularly and how it is approached — written from the technical work rather than from any one client’s job.
Disk order is part of the array structure. What happens when members are pulled to test them, and how the original sequence is derived from the disks.
Encryption and hardware failure are separate problems that have to be solved in a particular order. Why the drive is imaged before the key is applied.
On several external ranges the encryption key lives on the USB bridge board, not the disk. Why removing the drive from its case makes the data unreadable.
Decrypting a volume in place rewrites every sector. What happens when that process stops partway, leaving half the disk encrypted and half not.
A NAS that answers on the network but presents no shares has a working operating system and a broken volume. Why that is good news, and what not to run.
Adding a disk to a NAS rewrites the array layout while it runs. What happens when that process is interrupted, and why the old layout is still recoverable.
Drobo BeyondRAID and similar proprietary arrays use layouts no standard tool reads. Why a dead chassis is the real risk, and how these are reconstructed.
A firmware or BIOS recovery can clear a controller's array configuration, leaving healthy disks with no logical volume. How the geometry is derived back.
What is actually recoverable after an encryption run, why nobody decrypts current strains, and the first-day decisions that determine the outcome.
Storage Spaces, mdadm and dynamic disks fail differently from hardware RAID. How software arrays are reconstructed when the host will not import them.
A drive appearing as 1MB, 2MB or 8MB has entered a controller safe mode. What that means, why the flash is usually intact, and what not to try.
A power event can drop multiple array members at once. Why the second disk is often healthy, what stranded cache writes do, and why not to rebuild.