We are booking in new cases · Weekdays, 9am–5:30pm Urgent case? Call 0800 6890668
MHDR Maidenhead Data Recovery 0800 6890668 Send it in

Devices · network storage

NAS recovery in Maidenhead. It keeps serving files while it fails.

A NAS is the one device that carries on working while it fails: the shares still mount, the files still open, and so nobody stops. By the time the web interface is offering to rebuild, scrub or repair, those buttons have become the surest way to lose the volume. The most useful thing you can do is switch it off and leave it off, then send it in from Maidenhead whole, with the drives left in their bays.

No fee unless the data comes back Diagnosis free, then a fixed quote Post it in from Windsor, Slough or anywhere else

Describe the fault to an engineer
0800 6890668

NAS symptoms, and what each one means.

Nothing matches? Use the triage →
If you post it in: use a tracked, insured service addressed to our secure intake lab, and the return leg is paid at our end; if you would rather check the packing first, an engineer will go through it by phone. Each step is set out on the postage page.

The NAS makes we see most on the bench.

SynologyDSM on DiskStation and RackStation units — an SHR stack carrying Btrfs or ext4.
QNAPTS and TVS models on QTS or QuTS — first in line when ransomware sweeps start.
BuffaloTeraStation and LinkStation — the units that blink an E-number at you.
Netgear & WDReadyNAS and My Cloud — small boxes, large losses.

The words on screen, decoded.

A different fault? →
The symptomThe likely causeStart here
Synology: Volume CrashedDisk losses have overtaken what the parity coversCut the power before DSM begins repairs
Synology: Storage Pool DegradedOne member is failing while the shares still openEach hour powered is ground lost
QNAP: system volume not active / RAID unmountedThe box cannot assemble its own volumeAssemble it elsewhere
DeadBolt — WARNING: Your files have been lockedRansomware: .deadbolt appended to every filenamePhotograph it; leave the power alone
Buffalo E14: Cannot mount the RAID arrayA TeraStation or LinkStation unable to raise its arrayNote the E-number, then cut the power
Buffalo E16: The hard disk was not foundA member has failed, or gone missing entirelyThe data is nearly always still present
Buffalo E30: The hard disk may be brokenThe unit has ejected a memberLeave the rebuild alone

What happens to your NAS between arrival and return.

The most recent cases →
01

Booked in, then assessed at no cost Free

Nothing becomes chargeable until you have said yes to it. Each item takes a case number of its own the moment it arrives, an engineer establishes what has actually failed, and you are given a candid view of which files stand a realistic chance of returning. The single quote that follows is fixed, written down, and costs nothing.

Diagnosis at no costOne fixed quote, in writingNothing signed
02

Nothing starts before the copies do

Each drive is copied in full, difficult surfaces included, and all later work runs on those copies. The enclosure stays off, so the routine that caused the damage cannot repeat it.

Read-only images madeRebuilds ruled out
03

Unpick the layers

A Synology volume is rarely one thing: equal slices taken off unequal disks, an array raised over each set of slices, LVM holding those arrays together. QNAP, Netgear and Buffalo each arrange it differently. Every tier goes back up in software, lowest first.

mdadm and LVM unpickedSHR slices back in sequence
04

Put the file system right

Once the stack stands, attention moves to what sits on it. A damaged btrfs or ext4 volume is mended, the shares and folders come back carrying their own names, and a full listing goes to you to check before the job is closed.

btrfs or ext4 repairedShares under their own names
05

Opened, verified, and sent home

Nothing is billed until you have seen the recovered file list in full and told us to go ahead. What comes back arrives on new media, with the return journey at our cost, and the case stays open at this end until you have opened every file yourself.

You approve the list firstReturned on fresh mediaThe return post is ours

What tends to show up first

  • There is nothing proprietary at the bottom of SHR — mdadm arrays with LVM laid over them, built on equal slices cut from disks that do not match. The layers go back up in software, in sequence, from images and nowhere near the box. Whatever the Repair button is for, it is not for this.
  • 'Degraded' is a status with a deadline — repairing a RAID 5 or SHR pool asks every remaining disk for one complete read, and those disks were bought together and have aged at the same rate. One of them tends not to finish.
  • The enclosure is the cheap part — Buffalo and almost every other maker write the array's definition onto the members themselves, so a failed power supply is among the better things to find in a NAS.
  • A ransomed NAS is evidence before it is a repair — photograph the demand while it is still on screen, since a restart can remove the note and whatever identifier sits inside it. Our ransomware and forensics pages go on from that point.

The 2022 campaigns made the point plainly: DeadBolt's first sweep, on 25 January 2022, reached about 3,700 QNAP units that could be seen from the open internet, with more waves later in the year; eCh0raix and QLocker had already worked that same ground. The shared condition never varied — a box exposed to the internet, running firmware nobody had thought to update.

From the casebook, lately.

MH · MHD-2026-6785ON RECORD ✓

The rebuild that finished off a Wokingham mirror

The two red lights were survivable; the rebuild attempted afterwards was not, since it overwrote the box's own metadata. Both disks were imaged straight through their bad sectors, and the mirror was reassembled from whichever copy read more cleanly at each point, until the shared volume was whole again.

100% recovered5 days from arrival

Before it comes to the lab.

Do these now

  • Switch the unit off as soon as 'degraded' appears
  • Mark each disk with its bay before removing it
  • Post the drives alone, or the NAS complete if easier
  • Tell us the model, and whether the volume was SHR or plain RAID

Things best not done

  • Start a rebuild, or reach for 'repair'
  • Run a data scrub over a degraded pool
  • Accept Windows' offer to initialise the disks
  • Move disks between bays to test a theory

The questions that arise most often.

The box has stopped working. Has the data gone with it?

Usually not. Member order, chunk size and the volume above are written on the drives; the chassis only reads them back. Healthy disks in a dead box make for predictable work.

Whole unit, or just the drives?

Whichever suits you. A NAS can travel to the Guildford lab complete, drives still in their bays; with servers we would rather have the members alone, each marked with its bay. Imaging comes first either way.

What makes SHR different from ordinary RAID?

Synology Hybrid RAID exists so that mismatched disks waste no capacity. It cuts every drive into partitions of a common size, raises an array over each matching set, then joins those arrays under LVM as one volume. Recovery is unpicking that stack in sequence.

The volume has read 'crashed' since the rebuild. Is that the end of it?

That verdict is the enclosure's, not your data's. Imaged disk by disk and raised again in software, a volume DSM had given up on usually comes back whole.

Switched off, it keeps every chance it has.

Each further power-up asks more of a drive that has already begun to fail. Open the case first and let the free diagnosis tell you what is left.

0800 6890668