Open, and taking cases in · 9am–5:30pm, weekdays In a hurry? Call 0800 6890668
CDR Cardiff Data Recovery 0800 6890668 Book it in
CDR / The things we recover / NAS drives

Devices · Network storage

Cardiff NAS recovery. Everything on one shared box, then a bay light turns red.

A failing NAS gives no obvious sign. Shares still mount, files still open, and a dead disk can sit in the chassis for weeks before anybody notices. The danger comes next: DSM or QTS offers to scrub, repair or rebuild, and those buttons finish off more pools than the fault itself. Switch it off, and leave it off. Boxes come to us from studios in Cardiff's Roath, practices across the Vale, a builder's office in Caerphilly.

No files back, no fee on most jobs One fixed price, after a free diagnosis It comes to us by post from Barry, Pontypridd or Newport

Describe the symptoms to an engineer
0800 6890668

This comes in most weeks — routine work for the bench.

Nothing matching? Try the triage →
Posting it to us: post it tracked and fully insured to the intake lab, and the journey back is on us; ring first if you would like an engineer to check how it is packed before you seal the box. Every stage is set out on the posting guide.

The makes that arrive most often.

SynologyDiskStation and RackStation units on DSM, with btrfs or ext4 riding on an SHR stack.
QNAPTS and TVS boxes running QTS or QuTS hero — the ones ransomware crews scan for first.
BuffaloTeraStation and LinkStation: they show an E-number and go no further.
Netgear & WDReadyNAS and My Cloud — the family archive, all on one box.

Decoding the error messages.

Not seeing yours? →
What shows upWhat has gone wrongDo this now
Synology: Volume CrashedParity can no longer cover the disks that have gonePower off before DSM offers to put it right
Synology: Storage Pool DegradedA disk has dropped and nothing above it has noticedIt gets worse each hour it runs
QNAP: system volume not active; RAID unmountedThe box cannot mount the volume it builtAssemble it elsewhere
DeadBolt — WARNING: Your files have been lockedRansomware; every file renamed .deadboltPhotograph the screen, then touch nothing
Buffalo NAS error E14: Cannot mount the RAID arrayThe array is intact, but the box will not bring it upNote the E-number down, then pull the power
Buffalo NAS error E16: The hard disk was not foundA disk has died, or the box can no longer see itThe files are usually still sitting there
Buffalo NAS error E30: The hard disk may be brokenThe box has ejected a diskDo not allow a rebuild

From the parcel to your files coming back.

Cases we have logged →
01

A case number, and a diagnosis at no cost Free

The diagnosis costs you nothing. Every item that arrives is logged under a case number of its own, and an engineer works out what has actually failed — then tells you plainly which files can come back and which cannot. The price follows that: one fixed figure, in writing, and no work begins until you have read it and said go ahead.

Diagnosis at no chargeOne fixed figure in writingNothing owed yet
02

Everything starts with copies

Each disk is copied in full onto dedicated imaging hardware, tired patches and all. From then on the work happens on the copies. Your enclosure stays switched off here, so it cannot resume what it was doing to the pool.

Read-only copies madeNot rebuilt in place
03

Climb the stack

A NAS volume is rarely one thing. Synology stacks matched partitions, an md array over each set of them, then LVM across the top. Buffalo, Netgear and QNAP each have their own arrangement. We stand every tier back up in software, lowest one first.

mdadm and LVM unpickedSHR partitions matched up
04

Then the file system itself

With the stack standing, btrfs or ext4 gets its repairs. Your shares come back under the names you gave them, folder structure intact, and you see the complete listing and check it over before anybody here calls the job finished.

btrfs or ext4 repairedShares back under their own names
05

You approve it, then it goes back

Nothing is billed while you are still deciding. A complete listing of what came off the drive reaches you first, and the invoice only follows your yes. Files travel back on media bought new for the job, return postage ours, and we do not close it here until every one of them opens on the machine you will use.

The file list is yours to approveBack on media bought newThe postage back is on us

What we usually find first

  • SHR is nothing proprietary — it is mdadm with LVM laid over the top, sitting on partitions cut to match across drives of different sizes. Those layers go back one at a time in software, all of it off images, with the box itself powered down in another room. Repair has never once rescued a case like this.
  • Degraded is a deadline, not a status — bringing an SHR or RAID 5 pool back means asking each remaining disk for one unbroken read, cover to cover. They were bought together, fitted together, and have run the same warm hours since. One of them tends to stop partway.
  • The enclosure matters least — Buffalo, Synology and the others record the array's layout on the disks themselves rather than in the chassis, so a failed power supply is one of the easier things to see arrive at the lab.
  • Ransomware turns a NAS into evidence — get a photograph of the ransom note before anything is restarted, because a reboot can take away the note itself and the reference number printed in it. What to do from there is set out on the ransomware and forensics pages.

What 2022 settled: DeadBolt's first run, on 25 January 2022, took in somewhere near 3,700 QNAP units that were reachable from the open internet, and further waves followed through the months after. QLocker and eCh0raix had worked the same ground already. The victims shared two traits: a box exposed to the internet, and firmware left at whatever version it shipped with.

Straight out of the casebook.

CF · CDF-2026-0785LOGGED ✓

The Pontypridd NAS rebuild that made things worse

Two red lights, and the box could still have been saved. The rebuild someone started afterwards was what it could not survive: that wrote straight over the unit's own metadata. Both disks were imaged past the bad sectors, then the mirror was rebuilt piece by piece, each block taken from whichever copy read cleanest. The shared volume came back whole.

100% came back5 days after arrival

Before you send it off.

Start with these

  • Switch the box off as soon as it reports degraded
  • Label the disks by bay before they come out
  • Send the bare disks; the enclosure stays with you
  • Give us the model, and say if the pool was SHR or plain RAID

What to avoid

  • Begin a rebuild or accept repair
  • Start a data scrub on a degraded pool
  • Agree to Windows' offer to initialise the disk
  • Move disks between bays to see if it helps

What we get asked, week in, week out.

The enclosure will not power on at all. Are the files lost with it?

Usually not. Everything needed to stand the volume back up — bay order, stripe size, the layers above — is written on the disks, not into the case. Healthy disks in a dead enclosure make one of the better calls we take.

Disks, or the whole box?

The disks on their own. Our intake lab in Bristol takes bare drives, so pull them a bay at a time and mark each one with its bay number before it is packed. Post it fully insured, or drop it in. Nothing is read until every disk has been imaged.

What makes SHR different from ordinary RAID?

Synology Hybrid RAID exists so mismatched disks do not strand capacity. Each drive is cut into partitions that pair up across the set, an md array covers each pairing, and LVM binds those arrays into the volume you see. We unpick that stack tier by tier, from the bottom.

DSM has said Volume Crashed since the rebuild stalled. Is that it?

No. That is a statement about what the enclosure can still do, not about what the disks hold. Image each drive, assemble the pool in software, and a volume DSM gave up on generally reads end to end.

An unplugged NAS keeps whatever it still holds.

A failing drive has only so many starts left in it. Spend none of them. Keep the power off, and the free diagnosis will tell you what is still readable.

0800 6890668