Call us — 0141 404 0294
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · Two Very Different Events

Company Laptop Returned With the Data Gone

The enquiry came from an employer and described a machine handed back in an unexpected state. "One of my staff who is leaving has overridden the security on his MacBook and installed a new account, with all of the original accounts and data disappearing. I have the laptop and need to recover the original data if possible." The device is company property and so is the material on it, which makes this an ordinary recovery question rather than an access one. The technical picture turns on something not yet established, and it makes an enormous difference: whether a new account was added alongside the old data, or the machine was erased and reinstalled. Those look similar from the outside and have completely different odds.

MediaCompany-owned MacBook returned at the end of employment — original user accounts and data no longer present; a new account created on the machine
Reported situationMachine returned by a departing member of staff · original accounts and data absent · new account present · company ownership of device and data not in dispute · nature of the change not established
Fault classUndetermined between account-level change and full erase and reinstall — storage type and elapsed use governing recoverability
Equipment usedMachine use halted · storage imaged write-blocked before examination · residual account structures and filesystem history examined · encryption position established · findings reported in writing

The decode: two events, and why the storage type decides everything

Possibility one — an account change. A new administrator account created on an existing installation leaves the previous accounts and their data physically in place, simply not visible from the new one. Home folders remain on the volume, permissions changed or ownership reassigned. If that is what happened, the original material is likely intact and the recovery is straightforward — a matter of reading the volume properly rather than repairing anything.

Possibility two — an erase and reinstall. Wiping the machine and setting it up fresh produces the same visible result: a laptop with one new account and nothing else. But it is a different event technically, and on a modern Mac it is close to final. Erasing an encrypted volume is a cryptographic operation — the key protecting the data is discarded, after which the contents are mathematically meaningless regardless of what remains physically present. On solid-state storage, background housekeeping also clears freed blocks within minutes. Between them, an erase-and-reinstall on a recent machine usually leaves nothing recoverable, and that should be said before money is spent rather than after.

How the two are distinguished: by examination rather than assumption. A machine that has had an account added retains structures, logs and filesystem history from the previous installation; a machine that has been erased and reinstalled shows a fresh volume with a new creation date and none of that history. That determination is made on an image and it is the first thing done, because it decides whether any further work is worth commissioning.

What to do immediately: stop using the machine, and do not set it up further or add anything to it. If any of the original data survives, every hour of use reduces it — particularly on solid-state storage. The laptop should be powered off and left alone.

What to establish alongside: two things that cost nothing. Whether the machine was managed — enrolled in a device management system, which may hold configuration and encryption keys and sometimes reveals what was done and when. And where the company's data was supposed to live: material synchronised to company cloud storage, held in mail, or backed up centrally is unaffected by anything done to one laptop, and checking that first is free and frequently ends the matter.

The wider point for any organisation: a departing employee's device should not be the only place company material exists, and offboarding is more reliably solved by where data lives than by what happens to a laptop on the last day.

On the bench

Use of the machine was halted first, since on solid-state storage every hour of ordinary use runs more housekeeping against anything that survives. The storage was imaged write-blocked before any examination, and the image was then examined to establish which of the two events had occurred — residual account structures, filesystem history and volume creation records distinguishing an account change from a fresh installation. The encryption position was established alongside, since an erase on an encrypted volume discards the key and changes the answer entirely. The findings went to the company in writing before any further work was proposed.

The outcome

The two possibilities separated by examination, the encryption position established and the realistic odds reported in writing before commitment. Free assessment, one fixed written figure including VAT; where a drive has to be opened or a chip removed, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for any organisation in this position: adding a new account leaves the previous data physically in place and usually recoverable, while erasing and reinstalling discards the encryption key and — on solid-state storage — clears the freed blocks within minutes, which is close to final; those look identical from outside and are told apart by examining filesystem history on an image; stop using the machine immediately; and check company cloud storage, mail and central backups first, because material that lived there is unaffected by anything done to one laptop.

Company machine returned with the data missing

Power it off and leave it alone — don't continue setting it up, don't add anything to it, and don't let anyone "have a look". If any of the original data survives, continued use erodes it, and on solid-state storage that happens within minutes rather than days. Then establish what actually happened, because two very different events look identical: a new account added to an existing installation leaves the previous data physically present and usually recoverable, whereas an erase and reinstall discards the encryption key protecting it, which on a modern machine is close to final. That's determined by examining the filesystem's history rather than by looking at the desktop. Meanwhile check where the material was supposed to live — company cloud storage, mail archives, central backups — because anything held there is untouched by whatever happened to one laptop.

Company laptop handed back with the data gone?
Switch it off and leave it — call Glasgow Data Recovery on 0141 404 0294; imaged write-blocked, filesystem history examined to establish what actually happened, findings reported in writing first.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0141 404 0294