Call us — 01865 593000
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · NAS & Network Storage · A Deduction Worth Making

He Timed It, and the Timing Is the Evidence

His enquiry contains an observation that decides everything and he offers it almost as an aside. A ten-drive array that appears to have been compromised: "the volume has been formatted and removed and the system reset to factory configuration. The format looks to have been a quick format because it took 3 minutes. The array looks to be fine." Three minutes across thirty terabytes is not a wipe — it is arithmetically impossible as one, and that single figure establishes that the data is still there.

MediaTen-drive network storage array in a double-parity configuration, approximately 30TB — volume removed and unit reset to factory configuration by an unauthorised party; array structure intact
Reported situationNetwork storage appliance apparently accessed by an unauthorised party · storage volume formatted and removed · appliance reset to factory configuration · format operation observed to complete in approximately three minutes · array structure reported intact · contents required
Fault classIndex-level volume removal with content unwritten over — operation duration establishing that no surface write occurred; array geometry recoverable from member metadata
Equipment usedOperation duration assessed against write throughput before any conclusion · unit removed from service and from the network · all members imaged individually write-blocked · array geometry recovered from member metadata · volume assembled offline and structures rebuilt from surviving copies

The decode: why three minutes proves it

The arithmetic, which is the whole case: writing across thirty terabytes takes hours at any realistic rate. Even with ten drives writing simultaneously at full sequential speed, a complete surface pass is most of a day. Three minutes is not a slow wipe or a fast one — it is not a wipe at all.

What actually happened in those three minutes: new filesystem structures were written and the volume configuration was cleared. An index replaced and space marked as available — a bounded operation involving a tiny fraction of the array, which is exactly why it was quick.

So where the data is: exactly where it was. Nothing visited it, nothing overwrote it, and the only thing that could remove it now is new writing. The observation he made in passing is the strongest evidence in the case, and he made it himself.

Why the array being intact matters as much: double parity across ten members means the geometry is complex — stripe size, member order, parity rotation — and all of it is recorded in metadata on the disks. A factory reset clears the appliance's configuration and does not necessarily clear that, so the arrangement can be reconstructed and the volume assembled from images.

What must not happen now, and this is urgent: the unit must not go back into service. Not restored into, not rebuilt, not used for anything. Every write from this point lands in the space holding the previous contents, and an appliance returned to use will begin writing immediately — logs, indexes, thumbnails, whatever it does at rest.

Why it should also come off the network: whatever route was used to reach it is presumably still open. A device reset to factory configuration has default credentials and no longer has whatever protection it previously had, which is a worse position than before the incident rather than a fresh start.

The wider point about appliances of this kind: a storage unit reachable from the internet is a target, and units of this class are scanned for continuously. Convenience of remote access and exposure are the same setting, and the incident is a reason to reconsider it rather than only to recover from it.

What to establish alongside: whether anything was taken as well as removed. That is a separate question from recovery and worth asking.

On the bench

Operation duration was assessed against write throughput before any conclusion — a surface write across thirty terabytes requiring hours even with all members writing simultaneously, so a three-minute operation establishes that only structures were replaced and no content was visited. The unit was removed from service and from the network, a factory-reset appliance carrying default credentials. All members were imaged individually write-blocked, array geometry recovered from member metadata, and the volume assembled offline.

The outcome

The duration assessed against throughput before any conclusion, the unit taken off the network, and every member imaged before the volume was assembled offline. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: your own timing is the evidence. Thirty terabytes cannot be written in three minutes at any rate — so what happened was an index replaced and space marked available, and the content is untouched. Keep the unit off the network and out of service.

Storage volume removed by an intruder

Take the unit off the network and out of service immediately — don't restore into it, rebuild it, or use it for anything, because every write from now lands in the space holding your previous contents, and an appliance returned to use starts writing on its own. If you noted how long the format took, that figure may settle the whole question: writing across tens of terabytes takes hours even with every drive working at once, so an operation completing in minutes replaced an index and marked space available rather than erasing anything. It also needs disconnecting because a factory-reset appliance carries default credentials and whatever route was used is presumably still open.

Array wiped by someone who should not have had access?
Disconnect it entirely — call Oxford Data Recovery on 01865 593000; operation duration assessed against throughput, every member imaged individually, geometry recovered from member metadata and assembled offline.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.