The lab is taking new cases · 9am–5:30pm, Mon–Fri In a hurry? Call 0800 6890668
SDR Southampton Data Recovery 0800 6890668 Open a case

Devices · NAS boxes

Bought as a backup, now the only copy left.

Nobody plans it, but the box bought for backups ends up holding the only version of a family's or a firm's files. Once a volume degrades, every well-meaning option the NAS offers — repair, scrub, rebuild — is what finishes the data off. Switch it off instead.

Most jobs: no data back, no charge Free diagnosis & quote in writing Postal intake across all of Hampshire

Speak to an engineer about it
0800 6890668

Reading this page means you've come to the right place.

Can't see yours? Try the triage →
Sending it in: send your device by tracked, fully insured post to our secure intake lab — return postage is free — or ring us first and we'll talk you through packing it. Postage details sit on the contact page.

Brands and models we see here.

SynologyDiskStation and RackStation running DSM, on Btrfs or ext4, plus SHR arrays.
QNAPTS and TVS lines on QTS/QuTS — the ransomware crews' first choice.
BuffaloLinkStation and TeraStation, with those E-numbers on the front display.
WD & NetgearReadyNAS and My Cloud: modest hardware, business-sized fallout.

The precise wording your screen shows.

A different symptom? →
The wordingWhat that tells youFirst step
Synology: Volume CrashedMore members are gone than the volume could coverSwitch it off; skip DSM's repair
Synology: Storage Pool DegradedOne disk is on the way out; the pool still mountsRisk climbs with every hour it runs
QNAP: RAID unmounted / system volume not activeThe enclosure cannot put the array together any moreReassembly off the box
WARNING: Your files have been locked by DeadBoltRansomware: every file now ends .deadboltTake a photo of it; no restart
Buffalo E14: The RAID array cannot be mountedLinkStation/TeraStation cannot assemble its arrayRecord the code, power off
Buffalo E16: Unable to find the hard driveOne disk has dropped out or diedDisks normally still hold it all
Buffalo E30: The hard drive may be damagedThe box has kicked one disk outResist the urge to rebuild

How the recovery runs, step by step.

Browse recent cases →
01

Logged in, checked at no cost Free

As soon as it lands with us, your device gets its own case number. An engineer works out the fault, says what can genuinely be pulled off, then puts one fixed price in writing — no charge for diagnosis, no obligation, and no chargeable work until you approve it.

No-cost diagnosisQuote fixed in writingNo commitment
02

Copy each disk first

Each disk is copied read-only, weak sectors included, so the box is never handed the chance to pick a damaging rebuild back up.

Imaged read-onlyNo rebuild can restart
03

Take the stack apart

SHR cuts drives of unequal size into matching regions, lays an array over each and joins them with LVM; QNAP and the others each have their own stack. Those layers are reassembled in software, in the right order.

LVM and mdadm unpickedSHR regions in sequence
04

Mend the file system

On top of that reconstruction the ext4 or btrfs volume is put right, shares and folder trees come back, and the lot is checked against a listing you sign off.

ext4 / btrfs put rightShares back
05

Checked, returned, signed off

You sign off a complete list of the recovered files first; only then does the recovery fee fall due. Everything returns on fresh media, postage paid, and the job stays open until you confirm the files open at your end.

Sign-off on the file listFresh media suppliedReturn postage on us

First checks on the bench

  • There is nothing mystical about SHR — mdadm underneath, LVM on top, stacked over equal regions cut from unequal drives. Recovery means rebuilding those layers from images, off the box, in sequence. Pressing 'Repair' does the opposite.
  • 'Degraded' means the clock is running — repairing single-parity RAID 5 or SHR sweeps every sector of survivors of the same vintage, and that tips the next one over.
  • A dead enclosure ≠ dead files — on Buffalo and nearly all the rest the array is written on the disks; a blown PSU is one of the better verdicts we give.
  • Treat a ransomed NAS as a crime scene — capture the lock screen before any restart, since the note and its key can vanish when it boots. Our ransomware and forensics pages take it from there.

One campaign made the case: on 25 January 2022 DeadBolt began locking QNAP boxes that sat open to the internet; roughly 3,700 were counted in that first sweep, and further waves followed through the year, QLocker and eCh0raix having gone before it. Each victim was a NAS reachable from outside on unpatched firmware.

Out of the casebook.

EX · SDR-2026-0785CONFIRMED ✓

An Eastleigh agency's mirror, undone by its own rebuild

A two-bay box showing two red lights, then a home-made rebuild that wrote over its own metadata. Each disk was imaged through its bad sectors, the mirror rebuilt region by region from whichever image held the cleanest copy, and the shared volume returned intact.

100% retrieved5 days on the bench

While it's still with you.

Do

  • Shut the box off the moment it says degraded
  • Number each disk to its bay before you pull it
  • Post the disks alone, or the whole box if that is simpler
  • Say which model it is, and whether SHR or RAID was set

Avoid

  • Press 'repair', or kick off a rebuild by hand
  • Scrub a volume that is already degraded
  • Let a PC talk you into initialising the disks
  • Shuffle disks between bays to 'test'

Bench questions, straight answers.

The NAS unit has died — have I lost the data?

No. Everything that defines the array sits on the disks themselves; the enclosure only reads it. A failed box with sound drives is among the happier jobs we see.

Should I send the entire NAS unit?

Yes — send the whole NAS if you like; with servers we'd rather have just the drives, labelled. Do whichever suits you, because either way imaging the disks comes first.

How does SHR differ from standard RAID?

Synology Hybrid RAID splits drives of differing sizes into equal regions, builds a separate array over each set, then binds them with LVM — so a single volume can rest on layered arrays. Unwinding that in the correct order is the whole job.

The rebuild reported 'crashed volume' — does that mean nothing's left?

That is the enclosure failing, not your data disappearing. Rebuilding from drive images regularly restores volumes the NAS had already written off.

Whatever has gone wrong, keep it switched off.

Powering a damaged device up again costs you data. Start a case first; diagnosis is free whatever you decide.

0800 6890668