Hard drives
The drive that clicked for a fortnight
The situation: A desktop drive holding a small business's accounts started clicking. It was powered on repeatedly over two weeks while the owner tried recovery software, hoping it would "catch" a good moment.
What was actually happening: Clicking is failing heads. Each power-on risks the heads contacting the platters, and software cannot help a mechanical fault - it only keeps a dying drive working.
The takeaway: The honest lesson: the same drive, brought in on day one, is a routine mechanical job. Brought in after a fortnight of retries, the surface damage decides the outcome, not the lab. If your drive clicks, the cheapest thing you can do is switch it off.
Portable drives
The external drive that fell off the desk
The situation: A photographer's external drive - the only copy of a season's work - was knocked off a desk while it was copying files.
What was actually happening: Dropped while running means heads flying over platters at the moment of impact. The instinct to plug it back in "just to check" is the single most expensive habit in data recovery.
The takeaway: What the lab needs to know: how far it fell, onto what, whether it was running, and what it did when next powered. Those four details shape the whole approach - which is why we ask for them before the drive is ever spun up.
Laptops
The laptop that would not turn on
The situation: A student's laptop went black overnight, a week before a thesis deadline. Nothing on screen, no lights, no fan.
What was actually happening: A laptop that will not power on has a power or motherboard fault far more often than a storage fault - the files are usually sitting there intact, behind an electronics problem.
The takeaway: Two paths: extract and read the drive directly if it is removable, or board-level work if the storage is soldered down. Either way, the thing that turns this into a disaster is a repair shop replacing the board without being told the data matters.
Phones
The phone that went in the sea
The situation: A phone spent a few seconds in a rock pool on a summer afternoon, dried out, worked for three weeks, then died.
What was actually happening: Salt water is dramatically more corrosive and conductive than fresh. Corrosion continues quietly for days and weeks after the swim - which is why "it seemed fine afterwards" is such a common preamble.
The takeaway: Powered off immediately and cleaned promptly, salt-water phones are among the most recoverable jobs a lab sees. Left to dry and used for weeks, they become board-level rebuilds. We treat salt water as urgent for exactly this reason.
RAID & NAS
The array that was rebuilt onto itself
The situation: A four-drive NAS reported a failed disk. A replacement was fitted and a rebuild started - and part-way through, a second drive dropped out and the array would not come back.
What was actually happening: Rebuilds are the heaviest read a set of ageing drives ever faces. Drives that were quietly weak often fail during the rebuild, taking a degraded array past the point it can recover itself.
The takeaway: The ten-minute rule: when a drive fails in an array, stop, label the drive order, and get advice before rebuilding or reinitialising. An array that is powered down intact is a far better starting point than one that has been rebuilt twice.
Memory cards
The card that asked to be formatted
The situation: A wedding photographer's card prompted "card cannot be read - format?" at the end of a shoot. The prompt was accepted on the camera, hoping the images would still be there.
What was actually happening: That prompt means the file system is unreadable, not that the images are gone. Formatting writes a new empty file system on top of them and can overwrite the very structures a recovery needs.
The takeaway: Cancel, eject, and stop using the card - that is the whole answer. Cards brought in unformatted give a lab far more to work with than cards that were formatted and shot on again.