Data Recovery Case File · Apple Mac · When the Backup Needs Rescuing
The backup that wouldn't open anywhere else: a Time Machine drive's strange architecture, the crashed scans it caused, and the snapshots brought out whole
This is the double-failure every backup owner dreads, arriving in its classic form. The iMac crashed; Apple support's verdict was that its drive had probably died. The Time Machine external — the safety net — "appears to also have been corrupted as it crashed": plugged into a different laptop it was visible but apparently empty, no files in any normal browser. Recovery software told a more hopeful story — it could find the backup database's files and even peer inside them at his data — but every scan crashed his laptop before completing, which he attributed, shrewdly, to the machine "not being powerful enough." His request was simple: recover anything possible from the Time Machine drive. The good news starts with the fact that almost everything in his account has an innocent explanation — including the crashes.
| Devices | Time Machine external hard drive (primary patient); source iMac's internal drive declared failed by Apple support |
| Reported symptoms | TM drive mounts on another laptop but shows no files in Finder; recovery software locates the backup database and previews contents but crashes the host mid-scan, repeatedly |
| Fault class | A structurally dense backup format plus modest corruption from the crash — not the emptiness it resembled |
| Equipment used | Write-blocked imaging · ACE Lab Data Extractor (backup-database parsing; snapshot extraction) |
Why Time Machine drives look empty elsewhere — and why scanning them crashes computers
A Time Machine drive isn't a folder of copies; it's a database wearing a filesystem. To offer "your Mac at every hour," it stores each snapshot as a complete-looking directory tree in which unchanged files aren't duplicated but multiply-linked — one stored copy referenced from hundreds of snapshots — producing a structure of staggering internal density: millions of entries, layered permissions locking it to its source Mac, and conventions only Time Machine itself fully honours. Hence his two symptoms. On a foreign laptop, Finder meets the permissions and the alien structure and shows him the polite version of confusion: an apparently empty drive. And recovery software, gamely trying to enumerate the whole linked forest, does what his crashed three times — the scan's bookkeeping balloons with every multiply-referenced entry until the host machine, which genuinely isn't powerful enough because almost no desktop is, falls over mid-count. His diagnosis was right; his conclusion — try again harder — was the only wrong turn, and he'd stopped before taking it far. Beneath all of it, the "corruption" from the crash was real but modest: a backup interrupted mid-write leaves its newest snapshot ragged, not its archive — and the archive was what mattered.
The recovery — the snapshots, decanted
The drive was imaged once, write-blocked, and the parsing ran on the copy with tools built for the density that defeats desktops: the backup database walked as a database — snapshots enumerated, the link-forest resolved without re-counting it into oblivion, permissions bypassed at the forensic level where they're metadata rather than barriers. The most recent complete snapshot — the iMac as it stood at its last successful backup — was extracted whole: his user account, documents, photos, mail and settings in their proper tree, with the crash-ragged final snapshot mined afterwards for anything newer it had managed to capture before the interruption. Everything was verified by opening files across the set and delivered on a plain drive in ordinary browsable folders — his Mac's life, freed from the format that had guarded it too well — sized and structured for Migration Assistant to rebuild his next machine from directly.
Outcome
The backup did its job after all — it just needed an interpreter. And the case leaves behind the reframe every Time Machine owner should carry: an "empty-looking" TM drive on another Mac is almost never empty — it's a database declining to explain itself to strangers, and the data's real test is extraction, not Finder. Practical residue: don't reformat a TM drive that browses empty elsewhere, don't let repeated recovery-software scans crash-loop a machine against it (each crash risks writes; the structure will defeat the next scan too), and when machine and backup fail in the same event — his did, likely because the crash struck mid-backup with both connected — treat the TM drive as a patient, gently, rather than a spare part. One layer deeper than Finder, his entire Mac was sitting there intact. Most of them are.
Time Machine drive playing empty or crashing scans
Stop scanning — consumer tools drown in the backup's linked structure, and every host crash mid-scan is a roll of the dice on the drive. Never erase or "repair" a TM drive that shows empty on another Mac; empty-looking is the format working as designed. Keep it disconnected until it's imaged, note when the last successful backup ran, and plan on extraction of the latest complete snapshot — it's your whole machine, and it restores beautifully once it's out.
It's in there — call Bristol Data Recovery on 0117 332 1137 before another scan crash-loops.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.