Home / Devices / NAS External Drive

NAS Data Recovery Coventry

The box on the shelf hums away for years, and somewhere along the line it quietly became the only place the accounts and eight years of photographs both live. Then a bay light turns red, or a rebuild halts halfway, or one morning the fans are silent. Synology, QNAP, Netgear ReadyNAS and WD My Cloud volumes are rebuilt here from the disks themselves, and a four-bay unit out of an office in Warwick queues with everything else.

Looking at a NAS box costs nothing. What comes out of that examination is one written figure, agreed between us before anybody picks up a screwdriver: from £500 + VAT on a NAS, the figure following the number of disks in it.

Logical work is no fix, no fee. Four things sit outside that: electronic and mechanical failures, chip-level work, DVR jobs and forensic work, and anything physical is half up front. All five bands are laid out on the data recovery cost page, while data recovery services follows a postal job from the parcel to the answer.

// thirty faults, roughly by how often they turn up

Thirty ways it fails, and what lies behind each one

Tracing a symptom back to whatever caused it is where the job genuinely starts, and these thirty cover very nearly every box opened on the Oxford bench. A fault that is not on the list is not an unfamiliar one: describe it over the telephone and you will get a straight reading of the odds before you have spent a penny on postage.

Beeping, with a red light on one bay

A member has dropped out and the box is telling you so in the only way it can. If the array had redundancy it is now running without any, and a second failure takes the volume. The right response is to copy anything critical off while it is still readable, then stop, rather than to order a replacement disk and start a rebuild.

The dashboard calling the volume degraded or crashed

Degraded means one member is missing and the rest are carrying on. Crashed means the box has lost enough members that it will not present the volume at all. The two words look similar on a screen and they describe very different situations, so quote the exact wording when you ring, because it changes what happens first.

A rebuild that made everything worse

Rebuilding writes across every remaining disk at full speed for hours, and tired members that were coping with light use frequently fail under it. That is how a one-disk problem becomes a two-disk problem. If a rebuild is running now and the data matters, stopping it is nearly always the better decision.

A second disk failed during the rebuild

This is the classic way a four-bay box is lost, and it is not bad luck. The disks went in together, came off the same production run, and have run the same hours at the same temperature ever since. Both are imaged individually and the volume is assembled from the copies, which is array work starting at 500 pounds + VAT.

The setup wizard offered a new volume and somebody agreed

A NAS that cannot mount its array often presents itself as a new box wanting to be configured. Agreeing writes fresh array metadata over the top of the old. It is recoverable more often than not, because the file system underneath is usually left alone, but it makes the job longer and it must be declared on the booking form.

A dead enclosure and four perfectly healthy disks

Power supplies, backplanes and mainboards fail while the disks in front of them stay in good order. Moving those disks into another box of the same make sometimes works and sometimes writes new configuration over them. The safe route is to image every member first and assemble the volume from the copies.

It powers up and never finishes booting

Most of these boxes keep their operating system on a partition spread across the member disks, so a corrupted system area stops the unit starting even though the data volume is untouched. The array is reassembled here without the enclosure, so a box that will not boot is not by itself a serious problem.

Everything looks normal and the shares are empty

The volume mounts, the box is happy, and the folders are gone. That is a file system fault rather than a hardware one, or somebody or something has deleted the contents of a share. Turn the unit off rather than investigating over the network, because a mounted volume in use is a volume being written to.

Btrfs reporting checksum errors

Btrfs checks the data it reads against a stored checksum and refuses anything that does not match, which is a genuine safety feature and looks like catastrophe from the dashboard. Underlying disk errors are the usual cause. Snapshot history on these volumes is frequently the shortest route back, and it is looked at before anything more involved.

An ext4 volume that will not mount after a power cut

Losing power mid-write leaves the journal inconsistent, and the box declines to mount rather than risk making it worse. Backup superblocks and the journal itself usually allow a clean rebuild from an image with the directory tree in place. Power cuts are the single commonest trigger for this on a box with no battery behind it.

A box that was expanded and then failed

Adding disks or swapping small ones for larger reshapes the array, and a reshape interrupted part way leaves a volume that is neither its old size nor its new one. The layout has to be worked out from the members rather than from the configuration, which is slower but perfectly possible from images.

Disks moved into a different make of NAS

Synology disks in a QNAP, or the other way round, will not be understood, and the receiving box usually offers to initialise them. Even where nothing is written, the attempt costs time. Take the disks out, label them with the bay they came from, and let the array be read as it was built.

Ransomware that came in over the network

Network shares are exactly what these attacks look for, and a NAS mapped as a drive letter gets encrypted along with everything else. The hardware is fine. What comes back depends on the variant, on snapshots if any were genuinely enabled, and on what has been written since. It is priced as an ordinary array job and never as forensic work.

A shared folder deleted in the interface

Deleting a share through the web interface removes far more than dragging files to a bin does, and there is no undo. The blocks generally remain until something else takes their place, so the useful action is to shut the box down at once and leave it off. Every hour it stays up lowers the odds.

A firmware update that left it unbootable

Updates fail part way, or install correctly and disagree with the hardware, and the unit ends up in a recovery state or in a loop. The data volume is almost always untouched. Reassembling it away from the box is faster and considerably safer than repeated attempts to reflash the unit that is holding it.

Two disks put back in the wrong bays

Pulling members out to look at them and returning them in a different order confuses a box that identifies members by position. Most modern units cope; some do not, and some offer to rebuild. Photograph the front of the chassis before touching anything, and label each disk with the bay it came out of.

A single-bay box with no redundancy at all

One disk in a plastic case on the network, sold as a backup and used as the only copy. There is no array to reassemble, so it is ordinary single-drive work at 300 pounds + VAT, though the file system on it will be a Linux one rather than anything Windows knows. These are among the commonest units that arrive here.

The array is fine and the network is the fault

A box that has disappeared from the network may have a failed port, a stale address, a dead switch or a router that has been replaced. None of that touches the data. It is worth ruling out before anything is unplugged, because this is the version of the problem that costs nothing to fix.

An SSD cache that failed and took the volume with it

Losing a cache used only for reading costs nothing at all. Losing one that was taking writes is another matter, because material the network was told had been saved may still have been sitting on it when it died. Where write caching was switched on, say so, and send the cache devices along with the members, labelled, since they form part of the volume rather than an accessory to it.

Encrypted shares and a lost passphrase

Synology, QNAP and the rest can encrypt individual shared folders, and the passphrase or the key file has to be there before one will open. With it, the job is ordinary array work and it is priced as ordinary array work. Without it, nothing can be done by anybody, which is what the encryption was chosen for. Find the key file before the unit is packed rather than after it has arrived.

A volume that filled up and started behaving strangely

A file system with no free space left cannot always complete the housekeeping it needs to do, and Btrfs volumes in particular become awkward when they run out of room. Snapshots that nobody remembers enabling are a common cause of a volume being full when the folders suggest it should not be.

Snapshots that were never actually switched on

Most of these boxes can take snapshots and most of them do not, because the feature has to be enabled. People discover the difference on the day they need it. If snapshots were running, say so, because an earlier consistent state is frequently the quickest and cleanest way back to the files.

The only copy of a company's accounts

Small firms across the county use a four-bay box as the whole of their storage, with redundancy mistaken for backup. Redundancy survives a disk failing. It does not survive a deletion, ransomware, a fire, a theft or a controller writing rubbish across every member at once. That distinction is worth more than any hardware.

A disk that drops out and comes back

A member that disappears under load and returns on a reboot is failing, not sulking, and every cycle of dropping out and rejoining risks the array writing inconsistent data across the set. It is the warning stage. Getting the unit copied while it still assembles is much easier than reassembling it afterwards.

Bad sectors on more than one member at once

Disks bought together and run together age together, so it is common to find several members with unreadable areas rather than one obviously dead disk. Each is imaged individually with the difficult regions left until last, and the volume is assembled from whichever copy of each block reads cleanly.

Shingled disks that stall a rebuild

Some cheaper high-capacity drives write their tracks overlapping, which slows sustained writing to a crawl. Put one in an array and a rebuild can take so long that the box gives up on it, or another member fails during the attempt. It is worth knowing which disks are in your unit before you order a replacement.

A hardware RAID card inside a larger box

Where a proper controller is involved, the layout is set by the card rather than by the operating system, and the metadata sits in a format specific to that maker. Members are imaged and the arrangement derived from the images. The card itself stays with you and is not needed at this end.

A box built out of an old computer

Units assembled out of an old tower running Linux software RAID, TrueNAS or unRAID arrive fairly often, and the method is no different from a commercial box: copy every member, work out the arrangement from the copies, build the volume from those. Send every disk with a note of the order they sat in and which software was in charge of them.

A unit thrown out with the disks kept

People clear a cupboard, scrap a box that stopped working years ago and keep the disks in a drawer. That is usually enough. Bring or post every disk that was in the unit, labelled with its bay if it is known, and say which make and model the enclosure was, because that narrows the layout down before any work starts.

The dashboard is asking to initialise the array

Initialise, format and set up all mean the same thing here, and none of them is what you want. The box is offering it because it cannot read what is there, not because there is nothing there. Cancel, power down, and let the members be read in the state they are in.

The dashboard will ask to rebuild. Say no

A unit that has lost a member wants to repair itself and will keep asking until somebody clicks yes. It is worth understanding what agreeing involves. A rebuild reads every sector of every surviving disk at full speed for hours or days on end, and that is precisely the workload a second ageing member cannot take. The sequence that arrives here week after week is a first failure that went unnoticed for months followed by a second one part-way through the repair. Where a rebuild has already run and stalled, the set is in a worse position than before it started, because parity that is correct and parity that is wrong are now mixed across the members. That does not make the job impossible — every disk is imaged, including any the box has written off, and the volume is rebuilt from those copies rather than from your hardware — but the gap between a unit powered down at the first red light and one that has survived two rebuilds and a re-initialisation shows up both in the hours the job takes and in the size of what is handed back.

One of only two things that travels complete

Nearly everything else on this site is posted as a bare drive. A NAS is the exception, along with an external drive in its own case. Disks stay in their bays, caddies stay untouched, the power supply goes in the box, and the whole thing is posted exactly as it sits, because that is what Oxford's form asks for and the bay order then arrives with the chassis instead of having to be reconstructed. If the unit is genuinely too heavy to post — a large rack-mount, say — take the disks out instead, photograph the front first and write the bay number on each one. Unlabelled disks in a jiffy bag with no record of the order are still workable and simply add a day. Add a note as well, covering the make and model, the sort of volume it held, and anything that has already been tried. Knowing whether this is Synology Hybrid RAID on Btrfs or somebody's own mdadm arrangement removes a step before anything starts. Buffalo units have their own page here, since LinkStation and TeraStation boxes behave distinctively enough to be worth separating.

One disk failing is the only thing redundancy promised

That is the entire guarantee, and it is worth reading in an emergency because the prevention is inexpensive and the cure is not. Redundancy has nothing to say about a file deleted in error, ransomware arriving from an infected workstation over the network, a controller writing rubbish to every member simultaneously, a firmware update interrupted by a power cut, fire, theft, or an administrator accepting a wizard's offer to build a fresh volume. Each of those turns up here regularly, and in every one the redundancy worked exactly as designed and made no difference whatever. What would have made a difference is a second copy somewhere the network cannot reach — a drive that lives unplugged in a drawer, or a service the NAS itself has no rights to write into. Snapshots help where they exist, and a striking number of owners believe they have snapshots because their box supports the feature rather than because anybody switched it on. That takes a minute to check and nothing to put right.

The figure, and the order things happen in

A NAS is an array and starts at £500 + VAT, with the figure following how many members there are. A one-disk box carrying no redundancy at all is plain single-drive work at £300 + VAT, since there is nothing to put back together. The free examination finishes two working days after the unit is logged and produces one written figure before anything begins. Ransomware on a NAS is charged at the array rate like any other job of that shape and never at the investigation rate, whatever anybody else has quoted. Logical faults carry no fix, no fee; a member that failed mechanically or electronically does not, and half is payable up front on that portion, because head stacks and boards are bought for those specific disks. Every member is imaged before a single theory about the layout is tested, and nothing is written back to a disk that arrived here. A business that has stopped trading should say so on the telephone, and the job is marked when it lands.

// the tools it takes

What stands on the bench, and why any of it matters

Array work is done on copies and never on the disks that arrived. Every member is imaged first, every theory about the layout is tested against those images, and the reassembled volume is written to fresh storage. Nothing in this list ever writes to a member you sent.

Every member imaged before anything is assembled

Each disk is copied individually with hardware imagers, and the ones with unreadable areas get the same head-by-head treatment as any single drive. Only when there is a complete set of images does anybody start working out how the array was arranged.

Layout worked out without the enclosure

Stripe size, member order, parity rotation and offset are all derived from the images themselves. The box, the controller and the configuration file are useful when they arrive and are not required, which is why a dead enclosure is an inconvenience rather than a barrier.

Btrfs, ext4, XFS and ZFS reconstruction

The volume on top of the array is a Linux file system on almost every one of these boxes, and Windows will never make sense of a member connected on its own. Snapshot and transaction history is used wherever it exists, because an earlier consistent state is often the cleanest route back.

Filtered air for members that failed mechanically

A NAS job frequently includes one disk that has died properly. That one is opened under filtered air, given matched donor heads and imaged, and only then does it rejoin the set. Mechanical work takes 50% up front and sits outside no fix, no fee, and the rest of the job carries on while it is done.

A donor shelf for NAS-grade disks

IronWolf, Red, Purple and the enterprise families that go into these boxes need donors from the same firmware family, and those are held here and sourced where they are not. A four-bay unit where two members need physical work is a longer job than one where nothing does.

Write blocking on every port in the room

Members are connected through hardware blockers throughout, from the first inspection to the return parcel. Nothing on this side of the blocker is capable of writing to a disk you sent, which matters more on an array than anywhere else, because a single wrong write can invalidate the whole set.

// badges that turn up in the post

NAS makes handled here

Synology, the whole DiskStation rangeQNAP TS, TVS and TS-h seriesWestern Digital My Cloud and EXBuffalo LinkStation and TeraStationNetgear ReadyNASSeagate BlackArmor and Personal CloudTerramaster and AsustorDrobo, with a layout all its ownThecus and ZyxelHome-built Linux, TrueNAS and unRAID

Boxes and layouts that come through

These boxes are arrays, so the starting figure is 500 pounds + VAT and it climbs as members are added. The examination that comes first is free and closes two working days after the unit is logged in. A single-bay box holding one disk with nothing behind it is priced as ordinary single-drive work at 300 pounds + VAT. Ransomware here is charged exactly as any other array recovery and is never billed as forensic. No fix, no fee applies to the logical faults; members that have failed mechanically or electronically fall outside it and carry half up front. Two decisions do more damage than everything else on this page put together: starting a fresh rebuild on a set that has already lost a member, and agreeing when the box offers to initialise, format or set up a new volume. Neither of them ends the job. Both change the order the work has to be done in, so write them on the booking form.

Synology and QNAP, the two that fill the bench

Between them these account for most of the boxes that arrive. Synology units run Linux software RAID underneath with ext4 or Btrfs above it, and Synology Hybrid RAID is a layer over that which allows disks of different sizes to be mixed. The arrangement is documented well enough to rebuild from images without guesswork, and on the units running Btrfs an earlier snapshot is often quicker to reach than a full reconstruction, particularly after somebody has deleted a share. QNAP uses the same software RAID foundation with its own volume management on top, including thin provisioning, which adds a mapping layer that has to be unwound before the file system underneath makes sense. Both makes are routine work here. Neither needs its enclosure to reach the bench, though sending it whole is what the shipping form asks for and it does save a step.

Netgear, Western Digital and the consumer boxes

Netgear ReadyNAS units use X-RAID, which grows a volume as disks are added and therefore carries a more complicated history than a fixed array does, and that history has to be read before the current layout can be trusted. Western Digital My Cloud boxes are single-disk or two-disk mirrors with a Linux file system on them, which is why connecting one to a Windows machine produces an offer to format rather than a folder of files. Seagate, Terramaster, Asustor, Thecus and Zyxel units all arrive here too, and all of them come down to the same method: image the members, establish the layout, rebuild the volume from copies. Buffalo boxes are common enough to have a page of their own on this site.

Drobo, ZFS and the home-built units

Drobo built a scheme of its own called BeyondRAID, which mixes disks of different sizes in one pool and survives one failure or two depending how it was configured. It resembles no standard array, so those units are rebuilt entirely from what the drives themselves say, and the company having closed makes no difference whatever to the method. ZFS pools on TrueNAS and on home-assembled machines are another matter again. Their transaction history often allows a consistent earlier state to be reached, which is a real advantage, while a pool that has lost more disks than its redundancy covered is a harder job than anything a commercial box will hand you. Send every drive, note the order, and say what was running the set.

// getting it ready for the post

Before the box is taped shut — take the drive out if it comes out

This is the exception on the site: the box goes in the parcel as it stands. Disks stay in their bays, caddies stay on the disks, and the power supply comes with it, because that is what the Oxford form asks for and because the bay order then arrives with the hardware rather than having to be worked out from metadata afterwards. Where a unit is genuinely too big or too heavy to post, the drives can travel on their own, but photograph the front of the chassis before pulling anything out and mark each drive with the bay number it occupied. Send it tracked and insured to Oxford Data Recovery, John Eccles House, Oxford Science Park, Robert Robinson Avenue, Littlemore, Oxford OX4 4GP, or drive it down: fifty-five miles of M40 from Coventry, an hour in reasonable traffic, parking outside, and hand deliveries taken on weekdays from 9:00am to 5:30pm. No unit is collected from anywhere. Shut the box down cleanly before it leaves and ignore any prompt to rebuild, however often the dashboard repeats it. Where a business has stopped trading, say so on 0800 689 0668 and the job moves up the queue.

// getting your media to Oxford

Posting a device in — what goes in the box

Almost everything worked on here arrived in the post. A drive that is already in trouble has an easier time boxed, padded and insured than it does being carried round in a bag for an afternoon, and a parcel handed over in Coventry today is normally booked in at Oxford tomorrow morning.

As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.

  • Use a box or padded mailer with some rigidity to it, and pack around the drive until nothing shifts when the parcel is tilted. Mains adaptors, docks and leads are not wanted at this end.
  • Sending a RAID or a server? Only the member disks travel — not the chassis, not the controller — and each one wants its bay number written on it. Take a photograph of the front of the unit before anything is pulled; it costs nothing and now and again it saves a day.
  • Print the shipping and booking-in form (PDF), add a name, a number you will answer and a sentence on how the trouble began, and drop it in beside the media.
  • Most people use Special Delivery, which is tracked and covered; a courier of your own does the same job. You can also bring it: the Oxford reception takes devices over the counter, Mon–Fri 9:00am–5:30pm. Neither a Coventry counter nor a collection round exists.
// write this on the label

Oxford Data Recovery

John Eccles House
Oxford Science Park
Robert Robinson Avenue
Littlemore, Oxford, OX4 4GP

↓ Print the shipping & booking-in form (PDF)

Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.

Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.

// NAS recovery questions

Common questions

Usually not. Crashed is the box saying it has lost confidence in the set, and that is a remark about metadata rather than about the documents, so crashed volumes are very often rebuilt in full from images of the members. The things that make it worse are starting another rebuild and accepting an offer to create a fresh volume. Power the unit down and leave it.
The whole unit, disks in their bays, power supply included. It is one of only two exceptions on this site and it is the quickest route to an answer, because the bay order comes with the chassis. Only if the box is too large to post sensibly should the disks come out, and in that case photograph the front beforehand and mark each disk with the bay it occupied.
An array starts at £500 + VAT and rises with how many members it had, and the free examination finishes two working days after the unit is logged. A box holding one disk and no redundancy is £300 + VAT. Ransomware on a NAS carries that same array figure and is never billed as investigation work. Logical faults come under no fix, no fee; a member that failed mechanically takes half as a deposit first.
One of the better outcomes on this page. Power supplies and mainboards give up on their own timetable, and the volume is reassembled from images of the members rather than through the enclosure, so nothing about the recovery requires the original box to work. Sending it anyway makes the bay order plain instead of something that has to be deduced.
// the rest of the week's work

What else reaches this bench

// where to read next

Pages that go further than this one

The bench is ready whenever you are.

Looking at it costs nothing, one written figure follows, and the band governing this page is from £500 + VAT on a NAS, the figure following the number of disks in it.