Home / Devices / NAS External Drive

NAS Data Recovery Leicester

A box humming quietly on a shelf turns out to have been carrying the company accounts and eight years of photographs in the same chassis, which is how most owners learn it was never a backup. Then a bay goes red, or a rebuild gives up halfway, or the fans are silent one morning. Synology, QNAP, Buffalo, Netgear ReadyNAS and WD My Cloud volumes are put back together here from the member disks, and a four-bay unit out of an office in Wigston runs on the same bench as everything else.

Every NAS that arrives here is examined at no charge. The figure quoted afterwards is put in writing and settled before anybody reaches for a screwdriver: from £500 + VAT on a NAS, the figure tracking the disk count.

Logical recoveries carry no fix, no fee. The named exceptions to it are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs; physical work takes 50% up front. The five bands are set out in full on the data recovery cost page.

// thirty faults, roughly in order of how often they arrive

Thirty ways it goes wrong, and what sits behind each

Tracing a symptom back to the failure underneath it is where the real work begins, and these thirty account for all but a handful of the boxes opened at the Cambridge bench. A fault missing from the list is not an unfamiliar one — describe it on the telephone and you will get a straight view of the odds before you spend anything on postage.

Beeping, with a red or amber bay light

A member has dropped out and the box is telling you before it tells you anything else. On a single-redundancy volume that is one failure away from a total loss, and the rebuild that follows is the most stressful thing a set of tired disks ever has to do. Power it down and stop the clock.

The dashboard calling the volume crashed or degraded

Degraded means one member has gone and the volume is still readable. Crashed means the box has lost confidence in the set as a whole. The second word frightens people more than it should, because a crashed volume is very frequently reassembled in full from images of the members.

A rebuild that started and made things worse

Rebuilding reads every sector of every remaining disk, which is precisely the workload that finishes off a second tired member. Where a rebuild has stalled or failed partway, the array is in a worse state than before it began. Stop it, power everything down, and do not start another.

One disk failed, then a second one during the rebuild

The classic sequence, and the reason single redundancy on large disks is a thinner margin than the marketing suggests. It is not the end of the job. Both failed members get imaged, the good ones get imaged, and the volume is reconstructed from whatever combination gives the most complete result.

The setup wizard re-initialised the whole array

Somebody restarted the box, it offered to set up a new volume, and the offer was accepted. That writes fresh metadata and, on some models, begins a background format. The user data underneath is largely intact if the box was switched off quickly. Every hour it runs after that costs.

A dead enclosure with disks that look perfectly healthy

Power supplies and mainboards fail on their own schedule. The disks are fine and the box that understood them is not, which sounds worse than it is. The volume is reassembled from images of the members here, so a dead enclosure is not the end of anything.

A NAS that will not finish starting up

The unit powers on, the lights cycle, and it never comes up on the network. The operating system on a NAS lives on the disks themselves in a small partition on every member, and damage there stops the box without touching the data volume behind it.

Everything visible and the shared folders empty

The volume has mounted and the file system on it is damaged, which is a different problem from an array fault and needs a different repair. Recreating the shares does nothing. The volume is imaged and the file system rebuilt from the structures that survive.

A Btrfs volume reporting checksum errors

Btrfs notices corruption that other file systems quietly hand over, which is a virtue until the day it refuses to mount. Snapshots and the metadata trees frequently allow an earlier consistent state to be reached, and that work happens on images rather than on the original disks.

An ext4 volume that will not mount after a power cut

Journal damage or a lost superblock. Backup superblocks and the journal itself usually allow the volume to be reconstructed with everything in place. This is one of the more routine outcomes and one of the more complete ones.

A box that was expanded and then failed

Adding a disk to an existing volume rewrites the layout across every member while the data is being moved, which is the least forgiving moment in the life of an array. An expansion interrupted by a power cut or a failing disk leaves the set half in one geometry and half in another.

Disks moved into a new NAS of a different make

Layouts are not portable between manufacturers, and in several cases they are not portable between generations of the same manufacturer. A set that is put into an unfamiliar box will frequently be offered for initialisation, and accepting that offer is how a recoverable array becomes a much harder one.

Ransomware that reached the NAS over the network

Shares mounted on an infected machine get encrypted like any other folder, and boxes exposed to the internet get attacked directly. Snapshots sometimes survive because the attacker did not have the rights to remove them. It is priced as ordinary media, from 500 pounds + VAT for an array, and it is not forensic work.

A volume deleted by mistake in the interface

The management interface makes deleting a volume a small number of clicks. What that writes is metadata rather than the data itself, so provided the box was switched off promptly the contents are still there. What matters is how long it ran afterwards.

A firmware update that left the box unbootable

Updates on these units rewrite the system partition on every member simultaneously. Interrupted by a power cut, that leaves a box that will not come up and a data volume that is completely untouched behind it. The volume gets read from images and the box is somebody else's problem.

Two disks pulled out and put back in the wrong bays

Most modern boxes cope with this and some do not. Where the metadata has been damaged in the process, the order has to be worked out from the parity and the file system rather than from the labels. Photograph the front before removing anything, every time.

A single-disk NAS that has simply failed

The smaller boxes hold one disk and no redundancy at all, which makes them a shared folder rather than a backup. When that disk fails it is ordinary single-drive work at 300 pounds + VAT, and the surrounding hardware is irrelevant to the recovery.

A box that has been running untouched for eight years

Disks bought at the same time, run at the same temperature, doing the same work, tend to fail within months of each other. That is not bad luck, it is the arithmetic of a matched set. An array of that age that has just lost a member is very likely to lose another soon.

The array is fine and the network is the problem

A box that has vanished from the network is not necessarily a box with a data fault. Switch failures, address conflicts and a router that was replaced last week all present the same way. It is worth ruling out before anything is unplugged, and it costs nothing to ask.

An SSD cache that failed and took the volume with it

Read caching is harmless when it fails. Write caching is not, because a cache holding data that was never committed to the disks makes the volume inconsistent when it goes. Both cache devices and all the member disks have to travel, and it needs saying on the form which is which.

Encrypted shares with the passphrase lost

Several makers offer folder-level or volume-level encryption, and a properly implemented one does not yield. Where a key file or passphrase can be located the data comes back. Where it genuinely cannot, that is said plainly rather than charged for as an attempt.

A volume that is full and behaving strangely

Copy-on-write file systems behave badly at one hundred per cent capacity because they need free space to make any change at all, including deletions. A box that has filled up can end up unable to mount its own volume. It is recoverable, and the lesson is to leave headroom.

Snapshots that were never actually enabled

A great many owners believe they have snapshots because the feature exists. Checking that assumption is free and it takes a minute. Where snapshots do exist and did survive, they often make a ransomware or deletion job considerably shorter than it would otherwise be.

A NAS used as the only copy of the company accounts

Not a fault, a pattern. A box in the corner of an office with a redundant volume is not a backup, because redundancy protects against one disk failing and nothing else. It does not protect against deletion, ransomware, fire, theft or a controller that writes rubbish to every member at once.

A disk that keeps dropping out and coming back

Intermittent members are worse than dead ones, because the box keeps trying to bring them into the set and keeps writing metadata when it does. A member behaving that way should be left out rather than reinserted, and the whole unit should be powered down.

Bad sectors on several disks at once

Very common on arrays that have never been scrubbed. Each disk has a scattering of unreadable regions in different places, and no single member is complete. Imaging every member and combining the good regions is the only route, and it is one this bench takes regularly.

A Buffalo box that shows as an unformatted disk

Buffalo units use their own layout and their own file system arrangement, and a disk pulled from one and connected to a computer will be reported as unformatted. That is not damage. It is a format the computer does not recognise, and it is read here in the ordinary way.

A hardware RAID card in a larger box

Some units use a proper controller rather than software, and the configuration then lives on the card. If the card dies, the layout goes with it and has to be worked out from the disks themselves. That is routine here and it does not need a matching replacement card.

A DIY box built out of an old computer

Home-built units running Linux software RAID, ZFS or a packaged NAS distribution turn up regularly and are handled the same way. The layout gets worked out from the members. Say what it was built with on the booking form, because it saves a step at this end.

The unit was thrown out and the disks kept

Perfectly reasonable, and it makes the job harder rather than impossible. Without the enclosure the layout has to be derived entirely from the disks, and the bay order has to be reconstructed from the metadata. It works. It just goes quicker when the box comes too.

Stop the rebuild. That is the whole of the emergency advice

A NAS that has lost a member wants to rebuild, and the dashboard will keep asking until somebody agrees. It is worth understanding what that request involves. Rebuilding reads every sector of every remaining disk at full rate for hours or days, which is precisely the workload a tired second member cannot survive, and the classic sequence on this bench is one failure noticed late followed by a second twenty minutes into the rebuild. Where a rebuild has already stalled or completed badly, the set is in a worse state than before it started, because some correct parity and some incorrect parity have been written across it. None of that makes the job impossible. Every member is imaged, including the ones the box declared failed, and the volume is reconstructed from the copies rather than from your disks. But the difference between a set that was powered down when the first light went red and one that has been through two rebuilds and a re-initialisation is measured in days of work and in how much comes back. Power it off and ring.

A NAS travels whole, which is not the usual advice

Almost everything else on this site is sent as a bare drive. A NAS is the exception. Leave the disks in their bays, leave the caddies alone, put the power supply in the box, and send the unit as it stands. That is what the Cambridge shipping form asks for and it is the quickest route to a result, because the bay order arrives with the box instead of having to be derived from parity and metadata. Where a unit is genuinely too large or too heavy to post sensibly, take the disks out instead, but photograph the front of the chassis first and label every disk with the bay it came from. What is emphatically not wanted is a set of unlabelled disks in a jiffy bag with no record of the order. It can still be done, and it adds a day. The other thing worth including is a note of what the box is, what the volume was, and what has already been tried, because knowing whether you are looking at Synology Hybrid RAID on Btrfs or a home-built mdadm set saves a step before anything starts.

Redundancy is not a backup, and the difference matters

A redundant volume protects against one disk failing. That is the whole of what it protects against. It does nothing about a file deleted by mistake, ransomware arriving over the network from an infected workstation, a controller writing rubbish to every member at once, a firmware update interrupted by a power cut, fire, theft, or somebody accepting the setup wizard's offer to create a new volume. Every one of those turns up here regularly, and in each case the redundancy performed exactly as designed and was irrelevant. This is worth saying on a page people usually reach in an emergency, because the fix afterwards is cheap and the recovery is not. A second copy somewhere the network cannot reach, whether that is a drive that lives unplugged or a service the NAS cannot write to, would have prevented most of the jobs described on this page. Snapshots help too, where they exist, and a surprising number of owners believe they have snapshots because the feature exists rather than because it was ever switched on. Checking that takes a minute and costs nothing.

What it costs and what happens in what order

A NAS is an array, so it starts at £500 + VAT and rises with the member count. A single-disk box with no redundancy is ordinary single-drive work at £300 + VAT, because there is nothing to reassemble. The free assessment closes two working days after the unit is booked in and produces one fixed figure in writing before anything begins. Ransomware on a NAS is priced exactly the same as any other array job and is never charged at the forensic rate, whatever anyone else quotes for it. Logical faults are covered by no fix, no fee. Members that failed mechanically or electronically are not, and that part of the work takes half up front, because head stacks and boards are bought for your particular disks. Every member gets imaged before any theory about the layout is tested, and nothing is ever written back to a disk that arrived here. If the business has stopped trading, say so on the call and the job moves to the front of the list.

// what stands on the bench

The equipment involved, and why any of it matters

Array work happens on copies, never on the disks that arrive. Every member is imaged first, and every theory about how the set was arranged is tested against those images. Nothing on this bench is capable of writing back to a customer's disk at any point.

Per-member imaging before anything is assembled

Every disk in the set gets a complete read-only image with retry limits enforced in hardware. That includes the members the box declared failed, because a disk with a few thousand unreadable sectors still holds the overwhelming majority of what was written to it.

Layout analysis without the enclosure

Block size, member order, parity rotation, delay and start offset all derived from the images themselves. A NAS that has died completely takes its configuration with it, and none of that information is needed if the disks are readable.

Btrfs, ext4, XFS and ZFS reconstruction

The file systems these boxes actually use, rebuilt from images. Btrfs snapshots and ZFS transaction history frequently allow a consistent earlier state to be reached where the current one will not mount at all.

Filtered air for members that failed mechanically

Array members fail like any other disk, and the ones that clicked get head replacements under filtered air before they can be imaged. Mechanical work takes 50% up front and is one of the published exclusions from no fix, no fee.

A donor rack for NAS-grade disks

IronWolf, WD Red and the enterprise families, racked by model and firmware revision. Matched sets fail together often enough that having several of the same model on the shelf is the difference between starting this week and starting next.

Write blocking on every port in the room

Nothing a member disk touches here is physically capable of writing to it. That matters more on an array than anywhere else, because a single stray write to the wrong member can make a reconstruction impossible rather than merely difficult.

// badges that arrive in the post

NAS makes handled here

Synology, every DiskStationQNAP TS and TVS seriesWestern Digital My Cloud and EXBuffalo LinkStation and TeraStationNetgear ReadyNASSeagate BlackArmor and Personal CloudTerramaster and AsustorDrobo, and its own layoutThecus and ZyxelHome-built Linux, ZFS and TrueNAS boxes

Boxes and layouts that come through

A NAS is an array, so it starts at 500 pounds + VAT and rises with the number of members, and the assessment in front of that costs nothing and closes two working days after the unit is booked in. A single-disk box with no redundancy is ordinary single-drive work at 300 pounds + VAT. Ransomware on a NAS is priced exactly the same as any other array job and is never charged as forensic work. Logical faults are covered by no fix, no fee; members that failed mechanically or electronically are not, and those take 50% up front. Two things make these jobs harder than they need to be. The first is starting another rebuild. The second is accepting an offer to initialise or set up a new volume when the box asks. If either has already happened, say so on the booking form, because it changes the order the work is done in rather than ending it.

Synology and QNAP, the two that dominate the bench

Between them these two account for most of the boxes that arrive. Synology units use Linux software RAID underneath with either ext4 or Btrfs on top, and Synology Hybrid RAID is a layer over that which lets disks of different sizes be mixed. It is well documented and it reassembles cleanly from images, and where Btrfs is in use the snapshot history is frequently the shortest route back after a deletion or a ransomware run. QNAP units are built on the same foundations with their own volume manager and a thin provisioning layer that adds a step to the reconstruction. Neither needs its original enclosure to be recovered. What both need is for nobody to have started a second rebuild, because that is the single action that turns a straightforward job into a difficult one.

Buffalo, Netgear, WD and the consumer boxes

Buffalo LinkStation and TeraStation units are the ones people most often describe as having stopped working, and a Buffalo disk connected to a computer will always report as unformatted because the layout is not one Windows knows. That is normal and it is not damage. Netgear ReadyNAS boxes use X-RAID, which expands a volume as disks are added and consequently carries a more complicated history than a fixed set. WD My Cloud units are frequently single-disk devices sold in a way that leaves owners believing they are backups, and the EX models mirror across two. All of them reassemble here from images, and none of them require the original box, though sending it makes the bay order obvious rather than something to be deduced.

Drobo, ZFS and the home-built boxes

Drobo used a proprietary arrangement called BeyondRAID that pools disks of any size and tolerates one or two failures, and it does not resemble a standard array at all. Those units are worked from images with the layout derived from the disks. ZFS pools on TrueNAS and on home-built machines are a different proposition again, with a transaction history that frequently allows an earlier consistent state to be reached when the current one will not import. Home builds running Linux software RAID turn up regularly and are among the more straightforward jobs, because the metadata is well documented and sits on every member. Whichever of these you have, say so when booking it in, because knowing the arrangement in advance saves a day at this end.

// getting it ready for the post

Before you tape the box shut — take the drive out if it comes out

A NAS is the exception on this site: send the unit whole. Leave the disks in their bays, leave the caddies alone, and include the power supply. That is what the Cambridge shipping form asks for and it is the fastest route to a result, because the bay order comes with the box rather than having to be worked out from the metadata. If the unit is too large or too heavy to post sensibly, take the disks out instead, but photograph the front of the chassis first and label every disk with the bay it came from. Send it tracked and insured to Cambridge Data Recovery, Compass House, Vision Park, Chivers Way, Cambridge CB24 9AD, or bring it in: the lab sits two minutes off the A14 at Junction 32 with parking outside the door, and Leicester to that door is roughly seventy miles on the M1 south to Junction 19 and then the A14 east, about an hour and a half. Reception takes drop-offs Monday to Friday, 9:00am to 5:30pm. Nothing is collected. Before it leaves, power the box down properly and do not start another rebuild, however insistent the dashboard is. Ring 0800 689 0668 if a business has stopped trading and the job needs moving up the list.

// how the media reaches Cambridge

Sending a device — and the three exceptions

The post office does most of the work of getting a job here. A drive that is already unwell travels better boxed and insured than rattling around a car for a day of errands, and something dropped into a Leicestershire postbox this afternoon is generally logged in at Cambridge tomorrow.

The general rule is the drive travels and the machine stays behind — out of the laptop, out of the tower, out of the iMac, out of the recorder under the counter. This bench does not dismantle equipment, and a repair shop will do it while you wait. Three things are the other way round, and getting them wrong costs you the recovery: an external drive stays sealed in its own case, a NAS comes as a complete unit, and a WD My Passport or My Book travels whole with its cable, because on those the encryption key is held on the bridge board rather than on the disk — separate the two and the data becomes unreadable even to us. A Fusion Mac needs both of its drives, each labelled. The one thing nobody can work round is flash soldered onto the mainboard, as on Apple Silicon machines: if it will not come off, there is nothing to post.

  • A stiff box or a well-padded mailer, with enough packing that nothing moves when you shake it. Power supplies, docks and cables can stay at home unless the drive is one of the WD units above.
  • Running a RAID or a server? Send the member disks on their own, not the chassis or the controller, and write the bay order on each one — 1, 2, 3 and so on. Photograph the front of the unit before you pull anything, because that photograph occasionally saves a day of work.
  • Fill in the shipping and booking-in form (PDF) — a name, a number you actually answer, and a line on how the trouble started — and put it in the box.
  • Special Delivery is tracked and insured and is what most people use; your own courier is equally fine. Handing it over in person also works: reception at the Cambridge address takes devices across the counter, Mon–Fri 9:00am–5:30pm. What does not exist is a Leicester counter or anyone who comes to collect.
// write this on the label

Cambridge Data Recovery

Compass House
Vision Park, Chivers Way
Cambridge, CB24 9AD

↓ Print the shipping & booking-in form (PDF)

Address it to Cambridge Data Recovery. It is about seventy miles from Leicester if you fancy driving it — M1 south to Junction 19, then the A14 east — and the lab is two minutes off Junction 32 with parking at the door. Posting costs you a stamp and a day instead. Whichever you choose, you hear from us the moment it is booked in, and the free diagnostic closes two working days after that.

Not certain what belongs in the box? Ring 0800 689 0668 before you tape it up, or let the free online diagnostic ask the questions for you.

// NAS recovery questions

Common questions

Usually not. Crashed means the box has lost confidence in the set as a whole, which is a statement about metadata rather than about your files, and crashed volumes are very frequently reassembled in full from images of the members. What makes it worse is starting another rebuild or accepting an offer to create a new volume. Power it down and leave it.
Send the whole unit with the disks in their bays and the power supply included. That is the exception on this site and it is the fastest route to a result, because the bay order comes with the box. If it is too big to post, take the disks out, photograph the front of the chassis first, and label every disk with the bay it came from.
From £500 + VAT for an array, rising with the number of members, with the free assessment closing two working days after the unit is booked in. A single-disk box with no redundancy is £300 + VAT. Ransomware on a NAS is priced at the same array rate and is never charged as forensic work. Logical faults are no fix, no fee; members that failed mechanically take half up front.
Yes, and that is one of the better diagnoses on this page. Power supplies and mainboards fail on their own schedule, and the volume is reassembled here from images of the member disks rather than through the box. Nothing about the recovery needs the original enclosure to work, though sending it makes the bay order obvious rather than something to be deduced.
// the rest of the week's work

What else lands on this bench

// where to read further

Pages that take it further

Whenever you are ready, the bench is.

The examination is free, one written figure follows it, and the band covering this page is from £500 + VAT on a NAS, the figure tracking the disk count.