Call us — 0191 406 1051
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · NAS & Network Storage · The One That Came Back

A Returning Member Is the Whole Case

His enquiry set out an array's failure with unusual precision. A four-disk RAID 5: "HDD1 and HDD2 are fine. HDD3 and HDD4 failed at the same time. HDD3, after a cold restart, c"ame back. That last detail is the entire case, and it is the one people act on hastily. A four-disk RAID 5 survives the loss of one member and not two — so with two down, the array is offline and the data appears gone. But a member that returns changes the arithmetic completely, and what happens in the next few hours usually decides the outcome.

MediaFour-disk RAID 5 array — two members failing simultaneously, one subsequently returning to accessibility after a cold restart; two members unaffected
Reported situationFour-disk RAID 5 configuration · two members failing at the same time · array offline · one failed member returning after a cold restart · two members reported healthy
Fault classDual-member failure with one member intermittently available — array reconstructable from three members if the returning disk is imaged before it fails again
Equipment usedReturning member imaged first as the priority · all members imaged individually write-blocked (Atola TaskForce 2) · array assembled offline from images · no rebuild attempted on original disks

The decode: why the returning disk is urgent, and what not to do with it

The arithmetic: RAID 5 distributes parity so that any one member can be missing and reconstructed from the others. Two members down means the set cannot be computed and the array will not assemble. With three of four available, it can. So his returning disk is not a partial improvement — it is the difference between a recoverable array and an unrecoverable one.

Why it is urgent: a disk that failed, and then returned after a cold restart, is not healthy. It is intermittent, and intermittent disks return until they do not. Whatever caused it to drop — a marginal head, a struggling motor, a board fault worsening with heat — is still present, and cooling it down bought a window rather than a repair. That disk should be imaged, in full, before anything else happens. Not read from, not tested, not used to bring the array up: imaged, so that its contents are captured while it still cooperates.

The mistake this case invites: a returning member is exactly what tempts an owner to power the unit up and let it rebuild. That is the worst available action. A rebuild reads every remaining member intensively, from end to end, for hours — which is the heaviest load the set will ever see, applied to disks that have just demonstrated they are not reliable. It is precisely when the intermittent member drops again, and often when a third does too. It also writes, which forecloses options.

Why two failed simultaneously: worth noting for what it implies. Simultaneous failures in one enclosure usually share a cause — a power event, a heat problem, or disks from one batch reaching the same age together. That means the two "fine" members are not necessarily fine; they are simply the ones that have not failed yet, and they should be imaged too rather than assumed.

What the correct sequence is: power the unit down, remove all four disks labelled by bay, and image each one individually — starting with the returning member. Then assemble the array offline from the images, where nothing can attempt a rebuild and any wrong hypothesis about geometry costs nothing.

On the bench

The returning member was imaged first, as the priority above everything else, since a disk that failed and came back after cooling is intermittent rather than repaired and the window it offers is finite. All four members were removed, labelled by bay, and imaged individually write-blocked on the Atola TaskForce 2 — including the two reported healthy, since simultaneous failures usually share a cause and the survivors are the ones that have not failed yet. The array was then assembled offline from the images, where no appliance could attempt a rebuild.

The outcome

The intermittent member captured first, all members imaged individually and the array assembled offline from the copies. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone whose array lost two disks and got one back: that returning member is the difference between recoverable and not, because RAID 5 can compute one missing disk and not two — so image it immediately, in full, before reading from it or using it to bring the array up; a disk that returned after cooling is intermittent rather than fixed. Above all do not let the unit rebuild, because that reads every member hardest at the worst possible moment.

Array that lost two disks and one came back

Image the returning disk before anything else, and don't let the unit rebuild. That member is the whole case: a four-disk RAID 5 can compute one missing disk from the others but not two, so a disk coming back is the difference between a recoverable array and an unrecoverable one. But a disk that failed and returned after a cold restart hasn't been repaired — it's intermittent, whatever caused it is still there, and cooling bought you a window rather than a fix. So capture its full contents while it's cooperating rather than using it to bring the array online. A rebuild is the worst thing you can do here: it reads every remaining member end to end for hours, which is exactly when the intermittent one drops again. Power down, remove all four labelled by bay, and image each individually.

Array with a member that comes and goes?
Image it now, don't rebuild — call Newcastle Data Recovery on 0191 406 1051; returning member captured first, all members imaged write-blocked, array assembled offline from the copies.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.