Call us — 0141 404 0294
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Solid State & Flash · The Second You Did Not Wait

Ejected, Then Pulled Too Soon

Her enquiry was honest about a detail most people would not have noticed, let alone reported. A 16GB stick with about 8GB of documents on it: "The last time I worked with it on a Mac, I ejected, but I think I've took it out too quick. Other and previous Macs are not recognising it. My Windows laptop reacts when I plug it in, but is not showing the files inside — it shows as a mass storage device and that's it." She is a student and asked for a price. Her account is almost certainly the correct explanation, and it describes something worth stating plainly because the interface actively encourages the mistake: clicking eject starts a process rather than completing one, and the confirmation that follows is the part that matters.

Media16GB USB flash drive holding approximately 8GB of documents — removed immediately after an eject instruction; not recognised by macOS; enumerating on Windows without presenting a volume
Reported situationEject performed and device withdrawn before completion · no recognition on multiple Macs · Windows enumerating the device as mass storage with no accessible contents · documents required
Fault classInterrupted flush and close — filing structures left inconsistent; device enumerating with contents intact behind them
Equipment usedWrite-blocked imaging (DeepSpar USB Stabilizer 10Gb) · partition and filesystem reconstruction on the image · signature carving for anything beyond structural repair · documents verified by opening

The decode: what eject actually does, and how long it takes

Why it is not instantaneous: operating systems do not write to removable storage continuously. They hold recent changes in memory and commit them in batches, because writing in bulk is dramatically faster. Ejecting is the instruction to flush everything still held, complete any operation in progress, and close the filing structure cleanly by marking it consistent. That takes a moment — usually a fraction of a second, occasionally several seconds if a large amount was cached or the device is slow — and during it the device is being written to.

How the system tells you it has finished: the part people miss. On a Mac, the icon disappears from the desktop and the sidebar; until it does, the process has not completed. On Windows, a notification appears saying the device can be safely removed. Those are not decorations — they are the confirmation, and removing before them is functionally identical to not ejecting at all. Her instinct was right and her timing was a beat early, which is an easy thing to do and not a careless one.

What being a beat early left behind: the flush was interrupted partway, so the filing structure was caught mid-update — directory entries partly written, allocation records disagreeing, a journal describing a change that never finished. Nothing was erased; several small records were left mid-sentence.

Why her two platforms report differently, and why that is good news: Windows registering the device and showing it as mass storage means the stick enumerated — power, connector and controller are all working, which eliminates the serious hardware faults in one observation. The Macs showing nothing is a display philosophy rather than a worse fault: macOS declines to mount a filesystem it cannot parse and puts nothing on the desktop, so a damaged volume simply vanishes. Between them, the hardware is proved and the fault is placed in the filing structure with her documents intact behind it.

What to refuse: every offer to scan, repair, initialise or format, on either platform. Those write to exactly the structures a reconstruction rebuilds from, and on a stick this is the difference between getting her folders and filenames back and getting a heap of unnamed files.

For next time: wait for the icon to disappear, or for the notification. If a stick has just had a lot copied to it, give it a few extra seconds.

On the bench

The stick was imaged write-blocked behind the DeepSpar USB Stabilizer 10Gb in a single pass, so that everything afterwards happened against a copy and no platform's repair offer could reach the original. On the image the interrupted structures were reconstructed — the half-written directory and allocation records resolved and the incomplete transaction unwound — until the volume mounted from the copy with its folder tree, filenames and dates intact. Signature carving swept alongside for anything beyond structural repair, and her documents were verified by opening.

The outcome

The interrupted structures rebuilt from a write-blocked image and the documents verified and delivered. Free assessment, one fixed written figure including VAT, no recovery, no fee. The decode, for anyone who ejected and pulled too soon: clicking eject starts a process rather than finishing one — the system flushes writes still held in memory, completes anything in progress and closes the filing structure, and it tells you when that is done by removing the icon or showing a notification; pulling before that confirmation is the same as not ejecting at all; a device that enumerates on one platform proves its hardware while a Mac showing nothing is simply declining to mount a filesystem it cannot parse; and your files are intact behind records left mid-update, provided nothing repairs or formats it.

Pulled a stick straight after clicking eject

Don't let anything repair or format it — your documents are almost certainly intact behind records that were left half-written. Understand what happened, because the interface encourages it: clicking eject begins a process rather than completing one. The system flushes writes it was still holding in memory, finishes anything in progress and closes the filing structure, and it confirms when that's done — on a Mac the icon disappears, on Windows a notification appears. Pulling before that confirmation is the same as never ejecting. So wait for the icon to go, and give it a few extra seconds if you've just copied a lot across. From here, decline every offer to scan, repair, initialise or format on any machine, stop reinserting it, and take some encouragement from any computer that registers the device at all — that proves the hardware is fine.

Ejected and pulled a second too soon?
Your files are still there — call Glasgow Data Recovery on 0141 404 0294; imaged write-blocked, interrupted structures rebuilt on the copy, documents verified by opening. Free assessment.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0141 404 0294