Call us — 0141 404 0294
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · NAS & Network Storage · Everything Right After Everything Wrong

A New Array Created Over the Old One

This was the most technically accomplished enquiry in the entire archive, and it describes a disaster followed by exemplary handling. A four-disk RAID 5 suffered a dual disk failure; one failed disk later became accessible; and then, "before recovery actions could be completed, a new RAID array was created on the same disks, likely overwriting metadata and some data." Since then: "I have full sector-by-sector images of three of the original disks (the fourth is unrecoverable). All recovery attempts have been performed on images only." The original filesystem was NTFS. That second half is why this case is recoverable at all. He imaged everything and has touched nothing since — which is the single most valuable thing anyone in this position can do.

MediaFour-disk RAID 5 array following dual member failure — a new array subsequently created over the original members, overwriting array metadata; sector-by-sector images held of three original disks, the fourth unrecoverable; NTFS volume
Reported situationDual disk failure on a RAID 5 set · one failed member returning to accessibility · new array created over the original disks before recovery completed · original metadata overwritten · full images taken of three members · all subsequent work performed on images only
Fault classArray metadata destroyed by re-creation with member data substantially intact — original geometry to be derived analytically rather than read; parity permitting reconstruction from three of four members
Equipment usedWork conducted exclusively on the supplied images · original geometry derived by analysis of surviving data and parity relationships · NTFS structures located beneath the new array metadata · volume reassembled offline and losses mapped per file

The decode: what re-creation destroyed, and what it did not

What creating a new array actually writes: less than people fear, and in a very specific place. Array creation writes fresh metadata — the records identifying each disk as a member, its position in the set, the stripe size and the layout — into a small reserved region on each disk. Unless the creation process was allowed to run a full initialisation, the enormous bulk of the disks is not rewritten. So the array's description is destroyed while the striped data underneath it largely survives. That distinction is the whole basis for recovery here.

Why the original geometry now has to be derived rather than read: the description is gone, so the parameters must be established analytically — the order the disks were in, the stripe size, which direction parity rotated in, and the offset at which data began. Each of those is discoverable from the data itself: filesystem structures appear at predictable places, stripe boundaries reveal themselves where file content is interrupted, and parity relationships can be tested across candidate layouts until they hold consistently. It is careful work rather than guesswork, and it is exactly the work that a re-created array makes necessary.

Why three of four disks is enough: the encouraging arithmetic. RAID 5 stores parity distributed across the set specifically so that any one member can be lost and reconstructed from the others. With three original members imaged, the fourth can be computed rather than read — provided the geometry is correct. So the unrecoverable fourth disk is not fatal; it is precisely the situation the array design anticipated.

Why his discipline is the reason this is possible: the point worth stating loudly. He took full images before working, and every attempt since has been against copies. That means every wrong hypothesis about geometry costs nothing and can be retried; the originals cannot be degraded by experimentation; and if a promising approach turns out to be mistaken, the position is exactly where it started. Most cases of this kind arrive after somebody tested theories on the disks themselves, at which point each failed attempt has made the next one harder. He converted an unrecoverable situation into an analytical one.

The honest position: where the new array's metadata regions overlapped genuine data, those areas are lost — and with a fourth member unavailable, any region where a second member also fails to read cannot be reconstructed. So this is a strong candidate for substantial recovery with named losses rather than a guaranteed complete one.

On the bench

All work was conducted exclusively on the supplied images, as he had established, so that every hypothesis could be tested and discarded without cost. The original geometry was derived analytically rather than read — member order, stripe size, parity rotation and start offset established by testing candidate layouts against surviving NTFS structures and against parity consistency across the three imaged members. The missing fourth member was computed from parity rather than substituted. The NTFS volume was then located beneath the new array's metadata, reassembled offline, and every unreadable region resolved to the individual files it affected.

The outcome

The original geometry derived analytically, the missing member computed from parity and the volume reassembled offline with losses mapped per file. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone who has re-created an array by mistake: creating a new array writes fresh metadata into a small reserved region rather than rewriting the disks, so the array's description is destroyed while the data underneath largely survives; the original geometry must then be derived analytically from filesystem structures and parity consistency; RAID 5 permits one member to be computed rather than read, so a lost disk is survivable; and imaging every member first, then working only on copies, is what makes any of it possible.

Array that has been re-created or rebuilt by mistake

Image every disk before you do anything else, and then work only on the copies — that single discipline is what separates a recoverable situation from a lost one. Creating a new array writes fresh metadata into a small reserved area rather than rewriting the whole disk, so your data very probably survives underneath while the description of how it was arranged has gone. Recovering it means deriving the original layout analytically — disk order, stripe size, parity direction and start offset — by testing candidate arrangements against surviving filesystem structures. Every wrong guess is free if you're working on images and expensive if you're working on the disks. Take heart from the parity too: a RAID 5 set lets one missing member be computed from the others, so losing a disk entirely isn't the end. Don't initialise, rebuild or resynchronise anything further.

Array re-created over your original data?
Image first, experiment only on copies — call Glasgow Data Recovery on 0141 404 0294; original geometry derived analytically, missing member computed from parity, volume reassembled offline.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0141 404 0294