Taking in new cases now · 9am–5:30pm, weekdays In a rush? Ring 0800 6890668
BHDR Birmingham Data Recovery 0800 6890668 Get it seen
BHDR / Everything we recover / NAS systems

Devices · NAS enclosures

NAS recovery for Birmingham. Everything on one box — until a drive bay goes red.

Most hardware tells you plainly when it is broken. A NAS does not. Shares keep mounting, files keep opening, and the fault sits there for weeks with nobody the wiser. Then the web interface starts offering to rebuild, scrub or repair, and by that stage those three buttons are the fastest route to losing the pool outright. Power it down instead, leave it down, and post it to us from Birmingham.

Nothing recovered, nothing to pay Diagnosed free, then one fixed price From Walsall, Dudley or Coventry, it travels by post

Tell an engineer what it is doing
0800 6890668

This lands on our bench most weeks — it is ordinary work.

No match here? Start the triage →
Sending it by post: send it tracked and fully insured to our intake lab, and we cover the postage coming back; if you want the packing checked before it goes, an engineer will talk it through with you. Every step is written out on the posting page.

The NAS brands we see most often.

SynologyDiskStation and RackStation boxes running DSM, with btrfs or ext4 over an SHR stack.
QNAPQTS and QuTS hero on TS and TVS boxes — the first units ransomware campaigns look for.
BuffaloTeraStation and LinkStation, the ones that flash an E-number and stop.
Netgear & WDReadyNAS and My Cloud — home units holding everything.

What those messages mean.

Fault not here? →
What you seeWhat is behind itWhat to do
Synology: Volume CrashedMore members have dropped than the parity can coverShut it down before DSM tries to fix it
Synology: Storage Pool DegradedOne disk is fading and the shares carry on regardlessEvery hour it stays on costs you
QNAP: system volume not active; RAID unmountedThe unit cannot put its own volume togetherBuild it somewhere else
DeadBolt — WARNING: Your files have been lockedRansomware; every file now ends .deadboltTake a photo of it, and touch nothing
Buffalo NAS E14: Cannot mount the RAID arrayA TeraStation or LinkStation that cannot bring its array upWrite down the E-number, then power off
Buffalo NAS E16: The hard disk was not foundOne disk has failed outright, or is no longer seenIn most cases the files are still there
Buffalo NAS E30: The hard disk may be brokenThe box has thrown a disk outDo not let it rebuild

From arrival to the files going home.

Recent jobs on record →
01

Case opened, and the diagnosis costs nothing Free

Every item gets a case number of its own the day it lands. An engineer then works out what has actually failed and tells you plainly which files have a real chance of coming back and which do not. Only then does a price follow: one figure, fixed, in writing, and it costs you nothing to see it. Nothing is charged until you say yes.

The diagnosis is freeOne price, put in writingNothing agreed
02

Copies first, then everything else

Every disk is read end to end onto imaging hardware, weak surfaces and all. After that we only touch copies. Your enclosure stays off, so whatever it was doing to the array cannot start again.

Images taken read-onlyNo rebuild attempted
03

Work up the stack

There is seldom a single volume to find. On Synology it is matched partitions cut from disks of different sizes, an array over each group, LVM binding the lot. Buffalo, Netgear and QNAP each do it their own way. We rebuild every tier in software, starting at the bottom.

LVM and mdadm taken apartSHR partitions back in order
04

Sort out the file system

With the stack standing, the work moves up a level. Damage to btrfs or ext4 is repaired, your shares and folders reappear under the names you gave them, and you get the full listing to look over before we call the job done.

ext4 or btrfs mendedFolders back with their names
05

Approved by you, then posted back

No invoice is raised until the full list of recovered files has sat in front of you and you have said go ahead. Your data comes back on media we buy new, posted at our expense, and the job is not closed here until every file has opened on your own machine.

Your say-so on the file listYour data on new mediaWe cover the postage back

What the first look turns up

  • SHR is not a secret format — underneath it is mdadm with LVM sitting on top, running on matched partitions carved out of disks of assorted sizes. We put those layers back one at a time in software, working from images, with the enclosure nowhere in the room. The Repair button has never once helped a case like this.
  • Degraded means the clock has started — rebuilding an SHR or RAID 5 pool means reading every surviving disk from end to end, and those disks came out of the same box on the same day and have done the same hours since. One usually gives up part way.
  • The box is the least of it — Buffalo and the rest write the array's layout onto the disks rather than into the chassis, which is why a blown power supply is close to good news when a NAS arrives here.
  • A ransomed NAS is an evidence problem first — get a photograph of the demand while it is still on the screen, because a reboot can wipe the note and the case identifier printed inside it. Where to go next is set out on our ransomware and forensics pages.

The 2022 wave put the matter beyond doubt: when DeadBolt first swept through on 25 January 2022 it reached somewhere near 3,700 QNAP boxes standing open to the internet, and it came back repeatedly over the months that followed. eCh0raix and QLocker had already been across the same territory. Every victim had two things in common: a unit visible from outside, and firmware nobody had got round to updating.

Recent pages of the casebook.

BH · BHD-2026-8785RECORDED ✓

A Dudley rebuild that did more harm than good

Two red lights the box could still have come back from; the rebuild that followed could not, because it wrote over the metadata the unit kept for itself. Both disks were imaged past their bad sectors, and at every point the mirror was rebuilt from whichever copy read cleanest, until the shared volume stood whole again.

100% recovered5 days from arrival

Before the parcel goes.

Do this first

  • Power the box down the moment it says degraded
  • Label every disk with its bay number first
  • Post the disks by themselves, or the whole unit
  • Give us the model, and say whether it ran SHR or ordinary RAID

What not to do

  • Kick off a rebuild, or press repair
  • Scrub a pool that is already degraded
  • Click through the Windows initialise prompt
  • Swap disks around the bays to see what happens

The questions that come up every week.

The unit will not power up. Does that mean the files are gone?

Rarely. What the volume needs to stand again — disk order, stripe size, the layers above — lives on the disks, not the shell. Good disks inside a dead enclosure is a better outcome than most.

Send the box, or the disks?

Either works for a NAS. Post it to the Manchester lab as it stands, disks left in their bays, if that saves you a job. Servers differ — disks only, each labelled with the bay it came from. Nothing is touched before it is imaged.

How does SHR differ from a plain RAID set?

Synology Hybrid RAID stops odd-sized disks stranding capacity. Every disk is split into partitions that match across the set, an md array goes over each group, and LVM glues the results into one volume. Recovery means taking that stack apart, a layer at a time.

It has said Volume Crashed since the rebuild stopped. Is that final?

No. That is the box saying what it can no longer do, not what the disks hold. Copy each one, stand the volume up in software, and a pool DSM wrote off usually reads in full.

Nothing more is lost while the power stays off.

Every extra power-up takes something off a drive that is already going. Leave it switched off and let the free diagnosis say what still reads.

0800 6890668