Data Recovery Case File · Formatted & Logical Faults · Finding Is Not Reading
Recovery Software Finds Everything and Recovers Nothing
His enquiry described one of the most confusing experiences in data loss, and described it well enough to explain itself. A Seagate 2TB external drive: "when plugged into the Mac, it shows up the device and reads it but no data showing. If you try and load Disk Utility it freezes. I plugged it back in and it shows 700+GB of used data. I have tried some off-the-shelf scan software. They again freeze. One did do a full scan and found all the files, but when it came to recover or preview them" — nothing. Three separate observations, and together they form a coherent picture that is far more informative than any one of them. The headline is the last: a scanner listing every file while being unable to open a single one is not a broken program. It is a precise map of where the damage lies.
| Media | Seagate 2TB external hard drive — presentation inconsistent between connections, showing an empty volume and subsequently 700GB used; disk utilities and consumer scanners freeze; a completed scan enumerated files that could not be previewed or recovered |
| Reported situation | Device enumerates but content presentation varies between attempts · system disk utility hangs · multiple consumer scanners hang · one scan completed and listed files, none of which could be opened |
| Fault class | Degrading media with a readable catalogue over unreadable file content — host software stalling for lack of timeout control |
| Equipment used | Atola Insight Forensic head and surface assessment · PC-3000 Express with Data Extractor prioritised imaging under per-sector timeouts · repeat-read recovery of weak regions on later passes · filesystem rebuilt on the image; files validated by opening |
The decode: why finding is not reading
Where a filesystem's catalogue lives: the key to the whole case. The records describing what files exist — their names, sizes, dates and locations — are small and are stored in a concentrated area, typically near the front of the volume. The file contents are something else entirely: they are spread right across the disk's surface, wherever there was room when each was written. Those are two very different reading tasks, on two very different parts of the disk.
Why the scan found everything and recovered nothing: it follows directly. If the region holding the catalogue is still readable and the wider surface is not, a scanner reads the catalogue perfectly and produces a complete, accurate, encouraging list of every file on the drive — and then fails the moment it tries to fetch the actual contents, because those live in the regions that no longer return data. That is exactly his experience, and it is not a defect in the software. It is the drive telling him where the damage is: the small concentrated area is intact, and the large distributed area is failing. That is a media problem, not a filesystem one, and it changes what should happen next entirely.
Why everything freezes: the second observation confirms the first. Disk Utility and consumer scanners have no timeout control — faced with a sector that will not read, they wait, and retry, and wait again, because that is sensible behaviour on a healthy disk with an occasional glitch. On a drive whose surface is failing, they stall indefinitely and take the host with them. The freezing is not incompatibility; it is the software encountering exactly the unreadable regions his scan results implied.
Why it showed empty, then 700GB used: the third observation completes the picture. Inconsistent answers between connections mean the drive is returning different data on different reads — on one attempt enough of the volume's structures were read to report usage, on another they were not. A stable drive does not disagree with itself. That variability is the signature of marginal reads rather than of a filesystem that is simply damaged.
What follows: the answer to a drive whose surface is failing is not a better scanner but hardware-managed imaging: per-sector timeouts so a bad sector is budgeted and deferred rather than retried indefinitely, the healthy expanse captured first and completely while the drive is at its strongest, and the weak neighbourhoods revisited afterwards on their own passes, where patient repeated reads often recover data a single attempt cannot. Every further scan meanwhile is spending the drive's remaining margin on an approach that has already demonstrated it cannot work.
On the bench
All scanning stopped, which was the single most valuable step available. The Atola Insight Forensic assessed the heads and surface directly, converting his three observations into a measured map of where the drive still read cleanly and where it did not. Imaging then ran on the PC-3000 Express under Data Extractor with per-sector timeouts enforced and the sweep prioritised — the healthy expanse banked first and completely, the failing regions deferred to later passes where repeated patient reads recovered sectors that had defeated every consumer tool. On the completed image the filesystem was rebuilt, and the files his scan had merely listed were finally opened, verified and delivered on fresh media.
The outcome
The drive imaged under timeout control with weak regions re-read on later passes, and the contents verified and delivered. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone whose software found everything and saved nothing: a filesystem's catalogue is small and concentrated while file contents are spread across the whole surface, so a scanner can read the list perfectly and fail at every file — which is not a software fault but a map showing the catalogue area intact and the wider surface failing; utilities freezing confirms it, because they have no timeout control and stall on unreadable sectors; and a drive that reports empty on one connection and 700GB used on the next is returning inconsistent reads. Stop scanning: the answer is one managed imaging pass, not a better program.
Software lists all your files but cannot recover any
Stop scanning — that result is telling you something specific rather than failing. File names and details live in a small concentrated area of the disk, while the file contents are spread across the entire surface, so a scanner can read the catalogue perfectly and then fail at every single file. What that means is that the small area is intact and the large one is failing, which makes this a media problem rather than a filesystem one, and no amount of better software addresses it. The freezing confirms it: consumer tools and system utilities have no way to limit retries, so they stall indefinitely on unreadable sectors. If the drive also reports different amounts of data on different connections, that's inconsistent reads rather than confusion. Every additional scan spends the drive's remaining life on an approach that has already shown it can't work — unplug it and have one managed imaging pass done with proper timeout control.
That is a map, not a malfunction — call Leeds Data Recovery on 0113 322 3083; surface measured, imaged under per-sector timeouts with healthy regions first, weak areas re-read patiently.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.