Data Recovery Case File · Portable Drives · Encryption Is a Layer
The Lock Opened and the Room Behind It Is Damaged
Her enquiry describes a sequence in which the security worked perfectly. An external drive after her laptop had "a minor meltdown — I tried plugging my hard drive back in, it's whirring away and I can unlock it, but it won't let me see any files." Unlocking succeeding is the whole encryption question answered — the password is right, the drive is readable enough to validate it, and what remains is an ordinary damaged volume that happens to sit behind a lock.
| Media | Encrypted external hard drive — rotating normally; unlock credential accepted; no volume contents presenting after unlock |
| Reported situation | Drive functioning normally until the host machine failed · drive reconnected afterwards · rotation audible · unlock credential accepted successfully · no files presenting after unlock · photographic content held |
| Fault class | Filesystem damage within an intact encrypted container — credential and header valid; host failure during use implicated |
| Equipment used | Unlock confirmed as successful before any conclusion · no repair permitted on the unlocked volume · imaged write-blocked at container level · decryption performed against the image using the owner's credential · structures rebuilt from surviving copies |
The decode: what a successful unlock proves, and what it leaves
What has to work for an unlock to succeed: the drive must power up, present itself, and return the protected header holding the encryption key. The password must decrypt that header correctly, and the result must validate. Every one of those steps happened. So the hardware works, the header is intact, and the credential is right — which disposes of the entire encryption question in one observation.
What remains once the lock opens: an ordinary filesystem, exactly as it would be on any unencrypted drive. Encryption is a layer applied over storage rather than a replacement for it — and a damaged filesystem inside an intact encrypted container is simply a damaged filesystem. The lock is not the problem and unlocking is not the fix.
Why her computer's failure explains it: the drive was connected when the host misbehaved. Whatever the machine was doing at that moment was interrupted, and if it was updating the filing structures those are now inconsistent. The drive itself was a bystander — it was written to badly by a machine that was failing, which is the commonest way healthy external drives acquire logical damage.
Why nothing appearing is consistent with a good outcome: a system that cannot make sense of a filesystem shows nothing rather than showing part of it. An empty view is not evidence of an empty drive — it is a refusal, and the content occupies the medium exactly as before.
The check that confirms it, and it works through the encryption: once unlocked, look at the volume's reported used space. If capacity is still consumed while nothing is listed, the files are physically present and unnamed.
Why the encryption changes the method without changing the prospects: the drive is imaged at container level and decrypted against the copy using her own credential, after which the filesystem is rebuilt exactly as any other would be. What it does mean is that her password must be kept — without it nothing is possible, whatever condition the drive is in, and that is the one irreplaceable element.
What must not happen: no repair run against the unlocked volume. It will be offered, since a mounted-but-unreadable volume is exactly what repair tools address, and it discards the entries a rebuild would recover.
On the bench
Unlock was confirmed as successful before any conclusion — a credential accepted requiring the drive to present itself, return an intact protected header, and validate, which disposes of the encryption question entirely. No repair was permitted on the unlocked volume. The drive was imaged write-blocked at container level, decryption performed against the image using the owner's credential, and structures rebuilt from their surviving copies.
The outcome
The unlock confirmed, the container imaged and decrypted against the copy, and the structures rebuilt. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: your unlock succeeding answers the whole encryption question — the hardware works, the header is intact and the password is right. What's behind it is an ordinary damaged filesystem, very likely from your laptop writing badly while it failed. Keep the password safe.
Encrypted drive that unlocks and shows nothing
Keep your password somewhere safe, and stop treating this as an encryption problem. A successful unlock proves a great deal at once: the drive powered up, presented itself, returned an intact protected header, and your credential decrypted it correctly. What's behind the lock is an ordinary filesystem, and a damaged one inside an intact encrypted container is simply a damaged filesystem — the encryption is a layer over storage rather than a replacement for it. Your computer failing while the drive was connected is the likely cause, since an interrupted update leaves the structures inconsistent. Check the used space once unlocked; if capacity is consumed, the files are there. Don't run a repair.
Keep the password — call Guildford Data Recovery on 01483 901310; unlock confirmed before any conclusion, imaged at container level and decrypted against the copy, structures rebuilt from surviving copies.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.