Data Recovery Case File · NAS & RAID · RAID 5
RAID 5, volume removed: the expansion that erased the map to twenty-four terabytes
Storage accidents cluster around moments of change, and NAS expansions are their favourite. Mid-way through adding four new 8TB drives to his QNAP, this customer's existing volume — four 6TB drives in RAID 5, freshly loaded with his entire media and photo library — got removed in the management interface. The drives were fine. The array was fine. The data was fine. And none of it could be seen.
| Device | QNAP 8-bay NAS; affected volume 4 × 6TB in RAID 5 (originally 3 drives, previously expanded) |
| Reported events | Volume accidentally removed while configuring a second storage pool for four new drives; data not knowingly deleted; NAS no longer presents the volume; owner examined the drives read-only with recovery software, saw partition structures, went no further |
| Fault class | Volume/pool metadata removal above an intact RAID layer |
| Equipment used | Atola TaskForce 2 (parallel member imaging) · ACE Lab Data Extractor (RAID reconstruction) |
The enquiry
“I have 4×6TB drives in RAID 5 from my QNAP. They were originally three drives, expanded, and I'd moved all my data — movie library, photos — across. Everything was fine, but I accidentally removed the volume while adding a second RAID of four new 8TB drives. The data hasn't been deleted, but the NAS can't see it. I've tried recovery software and the partitions seem to be there, but I don't know how to recover them. Can you quote?”
What "removed the volume" actually removes
A modern NAS is a layer cake: physical drives at the bottom; the RAID 5 layer striping data and parity across them; a volume-management layer carving that RAID space into usable volumes; and the filesystem with your folders on top. "Remove volume" is an operation at the third layer — it tears up the directory of the building, not the building. The RAID beneath usually survives untouched; the filesystem above usually survives untouched; what's gone is the middle layer's description of where the volume begins and how it's laid out. That's why his read-only look with recovery software could see tantalising structure but couldn't assemble it: the tools were staring at 24TB of correct answers with the question missing. His instinct to stop right there — no initialising, no letting the NAS "repair", nothing written — kept this a reconstruction job rather than a salvage one.
Rebuilding the cake from images
All four members were imaged in parallel on the TaskForce 2 and the originals shelved; a removed-volume case is solved with arithmetic, and arithmetic is performed on copies. In Data Extractor, the RAID 5 layer was reassembled first — member order, stripe size and data/parity rotation established from the on-disk evidence and then proven, parity recomputed across samples until the four images resolved into one coherent 18TB expanse (four drives minus one drive's worth of parity). The drive set's history — three members grown to four — left its fingerprints in the metadata, and the reconstruction honoured the expanded geometry, not the original one; arrays that have been grown are exactly where naive rebuild attempts go wrong.
Above the RAID, the missing middle layer was reconstructed next: the removed volume's start and extent located by finding what it used to describe — the surviving filesystem's own signature structures — and the mapping rebuilt around them. With the layers re-stacked, the filesystem mounted from the virtual assembly essentially as the NAS had last seen it: the movie library, the photo collection, the folder tree, names and dates intact.
Outcome
Complete recovery — verified against the volume's own accounting, delivered to new storage, and finally copied onto the expanded NAS the way the original plan intended, this time with the library existing in two places during the move. That last clause is the case's engineering lesson wearing its plain clothes: expansions, migrations and pool changes are the highest-risk hours in a NAS's life, and they are precisely when your data should briefly exist twice. RAID 5 protects you from a dead drive. Nothing in the box protects you from the box's own menus.
Before you change anything on a NAS
Treat every pool, volume or RAID operation as potentially destructive, whatever the button says — and don't perform them on the only copy of anything. If a volume does vanish: power down, remove nothing physically without labelling bays, and above all don't create new volumes or accept repairs in the freed space; the old data survives only until something new is written over it.
That's usually fully recoverable — call Bristol Data Recovery on 0117 332 1137 before anything writes to those disks.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.