Data Recovery Case File · Formatted & Logical Faults · Selection, Not Carelessness
A Failing Drive and Its Replacement Look the Same in a List
His enquiry describes a migration that went wrong in the commonest possible way. Several old drives, one showing signs of degradation, and "an attempt to migrate data to another drive was carried out — accidental wipe of the wrong" device. The two drives in that dialogue were almost certainly the same capacity and probably the same model, because a replacement is bought to match what it replaces — and the only thing distinguishing them was a letter.
| Media | Several hard drives of over ten years, unused throughout — one degrading, one intended as a migration destination; erase applied to the incorrect device |
| Reported situation | Multiple drives of considerable age held · none used in over ten years · one drive showing signs of degradation · migration to a replacement attempted · erase operation applied to the wrong device · content required |
| Fault class | Index replacement on an incorrectly selected device — content present pending overwrite; degrading source drive requiring separate assessment |
| Equipment used | Devices identified by serial and content rather than by label · post-wipe write extent measured against capacity · each drive assessed independently · degrading source imaged under strict per-sector timeouts · previous structures recovered from surviving copies |
The decode: why the selection fails, and what the wipe actually cost
How drives are presented in a selection dialogue: by a letter or number, a capacity, and often a model string. All three are unhelpful here. A replacement bought for a failing drive is chosen to match it, so the capacities are identical and the models frequently are too.
Why the letter is the worst identifier of all: it is assigned by the system as devices appear, and it changes. A drive that was one letter yesterday can be another today, depending on what was connected first — so the one distinguishing detail is the one that is least stable.
Why this is a design problem rather than a personal failing: the interface presents two nearly identical entries and asks for an irreversible decision. Everybody who has done a migration has hesitated over that dialogue, and the ones who get it wrong are not less careful than the ones who get it right.
The prevention, and it costs nothing: physically disconnect every drive except the two involved. Two entries cannot be confused with four, and a drive that is not attached cannot be selected. Where that is impractical, verify by content — open the destination and confirm it is empty, or confirm the source holds what you expect — rather than trusting a label.
What the wipe actually did: almost certainly wrote a fresh index and marked the space available. It did not visit the files, which sit where they were, and only subsequent writing removes them. A migration that was abandoned the moment the error was noticed wrote very little afterwards.
Which drive was wiped matters a great deal, and it decides the priority: if the erase landed on the intended destination, nothing important was lost and the degrading source is still the urgent device. If it landed on the source, that drive now needs both a structural reconstruction and careful handling, because it was already failing before any of this.
Why the ages complicate it: drives unused for over a decade have thickened lubricant and aged boards. Each of them is a separate device with its own condition, and they should be assessed individually rather than as a collection.
What must not happen: no further migration attempts, and nothing written to any of them.
On the bench
Devices were identified by serial and content rather than by label — selection dialogues presenting drives by assigned letter, capacity and model, all of which coincide when a replacement was bought to match a failing drive, while the assigned letter is reallocated between sessions and is the least stable identifier available. Post-wipe write extent was measured against capacity, an erase replacing an index without visiting content, and each drive was assessed independently.
The outcome
Devices identified by serial and content rather than by label, the written extent measured, and each drive assessed independently. Free assessment, one fixed written figure including VAT per drive; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: the two drives in that dialogue were the same capacity and probably the same model, because a replacement is bought to match. The only thing distinguishing them was an assigned letter, which changes between sessions.
Before migrating between drives
Physically disconnect everything except the two drives involved — two entries can't be confused with four, and a drive that isn't attached can't be selected. That single habit prevents the commonest destructive mistake there is. The dialogue works against you: drives are listed by assigned letter, capacity and model, and a replacement bought to match a failing drive shares all three, while the letter is reallocated between sessions and is the least stable identifier available. Where disconnecting isn't practical, verify by content — open the destination and confirm it's empty — rather than trusting a label. And if it's already happened, write nothing further.
Write nothing further — call Oxford Data Recovery on 01865 593000; devices identified by serial and content, written extent measured against capacity, each drive assessed independently.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.