Data Recovery Case File · Portable Drives · Mechanical Failure
4TB WD My Passport beeping on connection — hardware-encrypted, heads replaced, data recovered through native USB
A year-old password-protected My Passport held the only copy of six years of personal project work. One day it stopped mounting and began emitting a rhythmic beep each time it was plugged in. This case file describes how our engineers diagnosed and recovered it.
| Device | Western Digital My Passport, 2.5″ portable, USB 3.0 |
| Capacity | 4TB (SMR platters, USB-native controller board) |
| Security | WD hardware AES encryption with user password set |
| Reported symptoms | Beeping on power-up; no longer appears in Windows; previously used daily for backups |
| Fault class | Head-stack failure with stiction (heads adhered to platter surface) |
| Equipment used | laminar flow bench · ACE Lab PC-3000 Express + Data Extractor · DeepSpar USB Stabilizer 10Gb · donor head-stack assembly |
| Data at risk | Six years of project files, photographs and documents — no other copy in existence |
The enquiry
“I have a WD 4TB My Passport with password protection that's around a year old, with personal projects from the last six years on it. I moved everything off my laptop because it was full. Now the drive has stopped working and only beeps when I plug it in.”
Two details in this message shaped the entire job before the drive arrived. The first is the beep. A healthy hard drive never beeps — it has no speaker. What the customer was hearing was the spindle motor being driven against a load it could not overcome, the coils singing at the drive's attempted start frequency. The second is the phrase password protection. On a My Passport that is not a software setting: the USB bridge controller encrypts every sector with hardware AES before it reaches the platters. Whatever we imaged from this drive would be ciphertext, and the recovery would need to end with a correct cryptographic unlock, not just a successful read.
Initial assessment
On the bench the drive drew current, attempted spin-up, stalled and retried — the beep cycle the customer described. There are two mechanical causes for this signature: a seized fluid-dynamic bearing in the spindle motor, or stiction, where the read/write heads have come to rest on the data surface instead of the parking ramp and adhere to the platter, anchoring it against rotation. The distinction matters because the procedures are entirely different, so no further power was applied until the drive was opened.
Inside the laminar flow bench, inspection settled it: the head-stack assembly was sitting on the platters, several millimetres off the ramp — a classic interrupted-parking event, consistent with the drive losing power or being unplugged mid-operation at some earlier point. Every subsequent start attempt at home had been the motor trying to shear the sliders free of the surface. The heads were released from the platters using the correct lifting technique for this family and returned to the ramp, and the platter surfaces were examined under magnification. The data area showed no scoring — the customer had, without knowing it, done exactly the right thing by giving up quickly rather than plugging the drive in for days.
Heads that have spent time adhered to a spinning-start surface cannot be trusted even when the platters survive. Microscopic inspection showed slider damage on two of the eight heads, so the original head-stack was retired and a donor assembly was sourced: same model family, matching micro-architecture and preamplifier revision, and a compatible head count — the criteria that determine whether a transplanted head-stack will fly correctly over these platters. The swap was carried out on the flow bench using platter-protection tools, and the drive then spun up cleanly and came ready.
Why a 4TB My Passport is harder than it looks
Three things make this specific device more demanding than a standard desktop drive. It is USB-native — the controller board has no SATA interface at all, so there is no conventional connection to fall back on; firmware access and imaging both have to happen through the USB port itself. It is SMR — shingled recording, where tracks overlap like roof tiles — which punishes random access and makes an aggressive, naive cloning attempt actively harmful. And it is hardware-encrypted, so a perfect sector-level image is still unreadable until the encryption is resolved.
The recovery procedure
The drive was connected to the PC-3000 Express through the DeepSpar USB Stabilizer 10Gb, which sits inline on the USB link and gives us hardware-level control that a normal computer port cannot: the ability to power-cycle and reset the drive on our terms, keep the link stable through read errors, and prevent the operating system from ever touching the device. Before any imaging, the drive's ROM and complete service-area module set were backed up — the firmware copy that means that whatever happens next, we can always return the drive to this state. Background processes that would let the drive "help" — automatic sector reallocation, offline self-scans, SMART logging — were disabled, because a recovering drive writing to itself is a recovering drive destroying evidence.
Imaging then ran in Data Extractor as a head-by-head, multi-pass job. The first pass ran with minimal retries and long-block sequential reads — sympathetic to the SMR layout — banking everything the transplanted heads could read easily; on this pass the drive returned the overwhelming majority of its surface without protest. Subsequent passes returned to the skipped regions with adjusted timeouts and per-sector retries, with the Stabilizer clearing the resets each time the drive fell over a difficult patch. The result was a sector image with coverage in the high ninety-nines, with the small remainder confined to the region where the heads had been resting.
Then the encryption. The image at this stage was AES ciphertext. Using Data Extractor's support for WD's security scheme, the drive's encrypted key material was extracted from its service data and combined with the password the customer supplied at intake to derive the data-encryption key, and a decrypted logical image was generated. It is worth saying plainly: the customer knowing their password mattered. Where a My Passport password has been lost, the options narrow sharply to attacking the extracted key material — something we can attempt with Passware Forensic against realistic candidate passwords, but never guarantee. Hardware encryption is doing its job even when its owner wishes it weren't.
The decrypted image mounted as the customer's NTFS volume. The final stage is the one no automated tool performs: verification. The directory tree was checked against the drive's own metadata for completeness, file signatures were validated across the project folders, and a sample of documents, images and video files was opened and inspected — because "files listed" and "files that open" are not the same claim. The verified data set was delivered on a new encrypted external drive, and the original drive was returned with the job.
Outcome
Six years of otherwise-unbacked-up work came off a drive that arrived unable to complete a single revolution. The decisive factors were the ones this case file is really about: the customer stopped power-cycling the drive early, the platters were opened only in a controlled environment, imaging ran through hardware built for unstable USB-native drives rather than a desktop USB port, and the encryption layer was handled with the drive's own key material rather than wished away. A beeping My Passport is a recoverable device — right up until it's been forced to keep trying.
If your drive is beeping
Disconnect it and leave it disconnected. The beep means the motor cannot spin the platters — usually because the heads are resting on them — and every further power-up drags the heads against the surface that holds your data. Do not open the drive, do not freeze it, and do not run recovery software against a drive that cannot even spin. Package it padded and get it to a lab with a clean-air bench and firmware-level imaging hardware.
Free diagnosis on all mechanical failures — call Bristol Data Recovery on 0117 332 1137 or send the drive to our lab for assessment.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.