Call us — 01483 901310
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Formatted & Logical Faults · Unknown History

The First Question Is Whether It Is the Same Drive

His enquiry has an unusual gap in it. A laptop "has been stolen, but I have already got it back. However, when I am powering on, only the firmware appears, which says there is no booting device. I would like to recover my data from the drive, but I don't know what the thief tried to do — whether my data was deleted, formatted, or overwritten." He is right that he cannot know. But there is a question that comes before all of those, and it has a factual answer he can establish today.

MediaLaptop solid-state drive from a machine stolen and subsequently recovered — firmware reporting no boot device; intervening handling unknown
Reported situationMachine stolen and later recovered by the owner · firmware reporting no boot device on power-up · no operating system apparently present · nature of any intervening action unknown · data recovery sought
Fault classUnknown intervening handling — component substitution, reinstallation, reset or secure erase each producing the same presentation
Equipment usedDrive identity verified against owner records before assessment · machine not powered repeatedly · drive assessed on a direct connection · written extent measured against total capacity · recovery scoped to surviving regions

The decode: the question first, then the three possibilities

The question: is the drive in that machine the one that was in it? Components are routinely removed from stolen equipment — sold separately, swapped for a smaller one to make a machine saleable, or taken out and replaced with something else entirely. A recovered laptop may also have been apart more than once. If the drive was substituted, his data is not in that machine at all, and every hour spent recovering from it is spent on somebody else's empty disk. The serial number on the drive, checked against a receipt, an asset record, a previous support case or a system report saved when the machine worked, settles it — and it costs nothing.

If it is the original, three things could have happened, and they differ enormously.

A reinstallation, which is the commonest and the most recoverable: an operating system installed to make the machine usable and saleable writes a new filesystem and tens of gigabytes of system files, working outward from the start of the available space. On a drive substantially larger than that footprint, everything beyond it was never touched — so files recovered from that region come back by carving, without folders or original names.

A reset or secure erase, which is the hard case: on solid-state media these are quick and thorough. A reset instructs the drive to discard its encryption key or to clear its mapping wholesale, and the result is final in seconds. There is no partial outcome to work with.

A failure to boot with nothing done at all: entirely possible. A machine mishandled, dropped or disconnected roughly may simply have lost its boot configuration or its drive connection, with the data untouched. The firmware message says no bootable device was found — it does not say the drive is empty, and the two are frequently confused.

The possibility worth checking if this was a work machine: full-disk encryption. If it was enabled, the data was unreadable to whoever had it — which is precisely the point of it — and the recovery key held by the employer makes this straightforward. That single fact would change the whole case.

What to do meanwhile: stop powering it on. And if the recovery involved the police, the machine may still be evidence, which is worth confirming before it is dismantled.

On the bench

The drive identity was verified against owner records before assessment — components being routinely substituted on stolen equipment, and a swapped drive meaning the data is not in the machine at all. The machine was not powered repeatedly. The drive was assessed on a direct connection, the written extent measured against total capacity to establish whether a reinstallation footprint sat within a larger untouched region, and recovery scoped to the surviving areas.

The outcome

The drive identity confirmed first, the written extent measured against capacity and recovery scoped to what survived. Free assessment, one fixed written figure including VAT; where a chip has to be removed, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone with recovered equipment: check the serial number first, because components are routinely substituted and a swapped drive means your data was never in the machine you got back. Then note that a firmware message about no bootable device does not mean the drive is empty — the two are constantly confused, and a mishandled machine may simply have lost its boot configuration.

Equipment recovered after a theft

Check the drive's serial number against a receipt, asset record or old system report before anything else — it costs nothing and it's the question that comes first. Components get removed from stolen equipment routinely, sold separately or swapped to make a machine saleable, so if the drive was substituted your data was never in the machine you got back. If it is the original, the outcomes vary enormously: a reinstallation writes a bounded amount and leaves everything beyond it untouched, while a reset or secure erase on solid-state media is quick and final. And a firmware message saying no bootable device doesn't mean the drive is empty — a machine handled roughly may simply have lost its boot configuration. If it was a work laptop, ask whether encryption was enabled.

Machine recovered after a theft with no boot device?
Check the serial first — call Guildford Data Recovery on 01483 901310; drive identity verified against your records before assessment, written extent measured against capacity, recovery scoped to surviving regions.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.