Data Recovery Case File · Cameras, Drones & Cards · Never Connect the Camera
Plugged In the Dashcam and It Started Recording
His enquiry describes a trap that destroys more dashcam footage than any accident does. "I have a dashcam. I need footage off it from yesterday, but when I plugged it into the computer it began recording and literally overwrote the file I needed. It was in the car and is on continuous rewrite. I needed the footage from 9:15am, but when I recovered the file it showed footage recorded in the evening — while the file time read 9:15am." Two things here. The first is an instruction that should be printed on every dashcam sold: never connect the camera — take the card out and read the card. And the second is that his strange result, a file with the right time and the wrong pictures, is a textbook description of what partial overwriting actually looks like.
| Media | Dashcam memory card in a loop-recording camera — camera powered via a computer connection and resumed recording, overwriting required footage; recovered file presenting original timestamp with subsequent content |
| Reported situation | Footage required from a specific morning time · camera connected directly to a computer to retrieve it · camera powered and resumed loop recording on connection · recovered file carrying the original entry with replaced content |
| Fault class | Partial overwrite by loop recording — directory entries surviving while referenced content was physically replaced |
| Equipment used | Card removed from the camera and imaged write-blocked (DeepSpar USB Stabilizer 10Gb) · overwrite footprint mapped · format-aware video carving of surviving regions by embedded timestamp · clips validated by playback |
The decode: why connecting the camera destroys footage, and the timestamp puzzle
Why the camera started recording: most dashcams have no separate power switch — they run whenever they receive power, and a USB connection to a computer supplies exactly that. Many models are designed to enter a data-transfer mode, but a great number simply boot as if the ignition had been turned on and resume their loop. So the act of connecting the camera to retrieve footage is, on those models, the act of starting the recording that overwrites it. The correct procedure is always the same: power the camera down, remove the card, and read the card in a separate reader. The camera should never be connected at all.
Why loop recording makes it worse: a dashcam writes continuously and, when the card is full, begins replacing the oldest material. So the footage most at risk is always the earliest still on the card — which, for someone needing yesterday morning, is precisely the material they came for.
The timestamp puzzle, which is the useful part: he recovered a file whose name and time said 9:15am and whose content was the evening's recording. That is not a glitch, and it is one of the clearest illustrations of overwriting in this archive. A file has two separate parts: the directory entry, which records its name, size, date and the location where its data begins, and the data itself, stored elsewhere. When new recording replaces the data but the directory entry survives, the entry keeps pointing at the same location — and now that location contains something else. So the file system faithfully reports a file made at 9:15am, and hands over whatever is currently at that address. The label survived and the contents were swapped.
What may still be recoverable: the honest picture. Overwritten regions are gone. But loop recorders do not necessarily overwrite in the order the directory suggests, and cards are rarely written perfectly evenly, so fragments of the morning's footage frequently survive in regions the new recording had not yet reached. The way to find them is not to trust the directory — which is now demonstrably unreliable — but to carve by content and sort by the timestamps embedded inside the video files, which are written at the moment of recording and cannot be swapped by a later overwrite.
What must happen now: the card comes out of the camera and stays out. Every minute the camera runs replaces more.
On the bench
The card was removed from the camera — the camera itself was never connected — and imaged write-blocked behind the DeepSpar USB Stabilizer 10Gb. The overwrite footprint was mapped on the image, and the directory was deliberately treated as unreliable given the demonstrated mismatch between entries and content. Recovery proceeded by format-aware carving of the surviving regions, with clips identified and ordered by the timestamps embedded inside the video data rather than by directory entries. Every clip was validated by playing it, and the losses were reported by position and by time range.
The outcome
The card imaged away from the camera, clips carved from surviving regions and ordered by embedded timestamps, with losses reported by time range. Recovery of deleted or overwritten data from memory cards and USB sticks is charged at a flat figure, payable upfront. The decode, for anyone retrieving dashcam footage: never connect the camera to a computer — many models power up and resume their loop on USB power, so the act of plugging it in starts the recording that destroys what you came for; take the card out and read the card. And if a recovered file carries the right time and the wrong pictures, that is partial overwriting made visible: the directory entry survived while the data it points at was replaced, so the label is intact and the contents were swapped. Recovery must carve by content and sort by embedded timestamps, not trust the directory.
Getting footage off a dashcam
Never plug the camera into a computer. Most dashcams have no power switch — they run whenever they receive power — and a USB connection supplies it, so a great many simply boot and resume their loop the moment you connect them. On a camera that has been recording over old footage, that means the act of retrieving your file is what destroys it. Power the camera off, take the card out, and read the card in a separate reader. If you've already lost footage this way, stop using the camera entirely and leave the card out. And don't trust what you see: a file with the right timestamp and the wrong pictures is what partial overwriting looks like — the directory entry recording the name and time survived while the footage it points at was replaced. Recovery has to work from the timestamps embedded inside the video itself.
Take the card out and leave the camera off — call Glasgow Data Recovery on 0141 404 0294; imaged write-blocked, overwrite mapped, clips carved and ordered by embedded timestamps.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.