Call us — 0191 406 1051
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Formatted & Logical Faults · Quarantine the Device

Saved to the Network, Sitting on the Laptop

This enquiry came from an internal IT team and describes a failure mode that produces no symptoms until it is far too late. "We have a device where the network home drive wasn't syncing as expected and an end user's data has gone missing. Last known saved file on the network drive is December 2025. We believe the files in question that haven't backed up are on the device's own drive." Their diagnosis is almost certainly correct. And there is one action that matters more than anything technical — because the standard handling for a returned device is the thing that would destroy the data.

MediaCorporate laptop internal solid-state drive — network home-drive synchronisation having failed silently; user data written locally and not replicated since a known date
Reported situationNetwork home drive not synchronising as expected · most recent file on the network dated to a specific month · user continuing to save in the normal way since · missing data believed resident on the device's local drive · device in the hands of internal IT
Fault classSilent synchronisation failure with local retention — data present in local cache and profile locations; device handling decisive
Equipment usedDevice quarantined against reimaging or reissue before any other step · local cache and profile locations enumerated · drive imaged write-blocked · server-side previous versions checked in parallel · recovered material reconciled against the sync date boundary

The decode: the instruction first, then the mechanism

The instruction, and it should go out today: that device must not be reimaged, reissued, wiped or returned to stock. When a machine comes back to an IT team it is normally rebuilt as a matter of routine, often within hours, and frequently by somebody who has not seen the ticket. A single reimage ends this permanently. The device should be flagged, physically separated, and labelled — not merely noted in a ticket, because the person who wipes it may never read one.

Why the data is on the laptop: redirected folders and offline-file caches work by keeping a local copy that syncs to the server in the background. That is deliberate — it lets people work while disconnected. When synchronisation breaks, the local half carries on working perfectly: files save, folders open, everything behaves normally. The user has no reason to suspect anything, because from their side nothing changed. The failure is entirely invisible from the seat of the person it affects.

Why the date is the most useful thing in the ticket: the last file on the network dates the break. Everything created or modified after that point exists only locally, which defines exactly what is at risk and gives a figure to reconcile the recovery against. It is also worth asking what changed that month — a client update, a credential change, a certificate expiry, a profile rebuild, a storage quota reached. Quota is the commonest and the quietest: a full home drive stops accepting new files, and the client may report the failure once and then stop.

Where to look, in order: the offline-files cache, which holds the local copies and is not the same as the visible folder; the local user profile, since desktop and documents may be redirected while other locations were never included; the redirected path itself; and server-side previous versions or snapshots, which may hold older copies of files that did sync and are worth checking in parallel because they cost nothing.

The organisational point, briefly: silent sync failure is a monitoring gap rather than a user error. A check for devices whose last successful sync is older than a threshold would have caught this in December, and it is worth raising alongside the recovery.

On the bench

The device was quarantined against reimaging or reissue before any other step — physically separated and labelled rather than flagged in a ticket, since a returned machine is routinely rebuilt within hours by someone who has not read it, and a single reimage ends the case. Local cache and profile locations were enumerated, the drive imaged write-blocked, and server-side previous versions checked in parallel at no cost. Recovered material was reconciled against the sync date boundary to confirm nothing after it was missing.

The outcome

The device quarantined first, local caches and profile locations enumerated, the drive imaged and the result reconciled against the date boundary. Free assessment, one fixed written figure including VAT; where a chip has to be removed, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for any IT team facing this: quarantine the device physically before anything else, because routine rebuild is the standard handling and it ends the case. Redirected folders keep a local copy that syncs in the background, so when sync breaks the local half keeps working perfectly and the user sees nothing wrong. The last synced date defines exactly what is at risk.

User data missing after a sync failure

Physically separate and label that device before you do anything else — don't just flag it in the ticket. Returned machines get rebuilt as routine, often within hours, frequently by someone who hasn't read the ticket, and one reimage ends this permanently. The data is very likely on the laptop: redirected folders and offline caches keep a local copy and sync in the background, so when sync breaks the local half carries on working perfectly and the user has no reason to suspect anything. Use the last synced date to define exactly what's at risk, then check the offline-files cache, the local profile, the redirected path, and server-side previous versions in parallel. Worth asking what changed that month, too — a quota reached is the commonest and quietest cause.

Device holding data that never reached the network?
Quarantine it before it's rebuilt — call Newcastle Data Recovery on 0191 406 1051; local caches and profile locations enumerated, drive imaged write-blocked, result reconciled against your sync date.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.