Data Recovery Case File · Portable Drives · Recent Means Exposed
The Newest Work Is the First to Go
His enquiry describes a failure in progress with a very particular shape. An external drive that is "visible when plugged into the computer, but has started to fail. Running very slowly, and certain folders — those I have recently worked on — show as having nothing in them and cannot be copied to the computer. Other folders and files can be copied." That is not a coincidence and it is not random. Recently used folders failing while older ones copy cleanly follows directly from how a filesystem works, and it means the material most at risk is the material he most needs.
| Media | Mac-formatted external hard drive in progressive failure — access slow, recently modified directories presenting as empty and failing to copy, older directories copying normally |
| Reported situation | Drive visible and mounting · access notably slow · recently worked directories presenting as empty · those directories failing to copy · older directories and files copying without difficulty · degradation ongoing |
| Fault class | Progressive read failure concentrated in frequently rewritten structures — recently modified directory entries unreadable; content present |
| Equipment used | Copy attempts on failing folders discontinued · readable content secured first in priority order · imaged write-blocked under per-sector timeouts with weak regions revisited · directory structures rebuilt on the image · files validated by opening |
The decode: why recent work fails first
What slowness means here: the drive is retrying reads internally — attempting a region, failing its checksum, and trying again. That is the first symptom of physical read degradation and it is why everything feels sluggish.
Why the recently used folders are the ones failing, and this is the mechanism: a directory entry is rewritten every time its contents change. A folder worked on this month has had its structures modified repeatedly and recently; a folder untouched for two years has structures written once, long ago, and never disturbed since. Frequently rewritten structures spend far more time being written — and a region being written while a drive is degrading is a region where an incomplete or unverified write is far more likely to land.
So the pattern follows from usage, not from luck: the more a folder was used, the more chances its structures had to be caught by a failing write, and the more likely they are now unreadable. That is why active project folders read as empty while the archive folders beside them copy perfectly.
Why "shows as empty" is better news than it sounds: an empty-reading folder means the directory entries listing its contents could not be read. The files themselves are elsewhere on the drive, in the data area, and nothing has happened to them. A folder that appears empty is a folder whose index is unreadable, not a folder that has been emptied.
The instruction that matters right now: copy everything that does copy, immediately, in priority order — and stop retrying the folders that fail. Every attempt on an unreadable directory is sustained reading of the exact regions that are failing, on a drive that is degrading, while the material that would still come off sits waiting. This is the commonest way people convert a partial loss into a larger one.
Why the failed folders are not lost: working from an image, directory structures can be rebuilt from their surviving backup copies, and where those are gone the files are identified by their own signatures. Both routes need the drive captured before it degrades further.
Why this connects to the wider pattern in this archive: the same inverse relationship appears after a repair utility runs — recent work removed, old files intact. Here it is happening without any repair at all, which shows it is a property of how filesystems are written rather than an artefact of any tool.
On the bench
Copy attempts on the failing folders were discontinued, each being sustained reading of exactly the regions that fail while the readable majority remained at risk. Readable content was secured first in priority order. The drive was imaged write-blocked under per-sector timeouts with weak regions revisited on later passes, and directory structures rebuilt on the image from their surviving backup copies — an empty-reading folder indicating unreadable entries rather than removed files. Files were validated by opening.
The outcome
The readable material secured first, the drive imaged under timeout control and the failing directories rebuilt from their surviving copies. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: recently used folders fail first because their directory entries are rewritten every time their contents change, so they have spent far more time being written — and a write landing while a drive degrades is where damage settles. A folder reading as empty has an unreadable index, not removed files.
Recently used folders reading as empty on a failing drive
Copy everything that still copies right now, most important first, and stop retrying the folders that fail — each attempt is sustained reading of exactly the regions that are failing, while the material you could still save sits there. The pattern isn't bad luck. A folder's directory entries are rewritten every time its contents change, so a folder you've worked on this month has had its structures modified repeatedly and recently, while one untouched for years was written once and never disturbed. Frequently rewritten structures spend far more time being written, and a write landing on a degrading drive is where damage settles. A folder showing as empty has an unreadable index rather than removed files — they're still there.
Secure the readable material first — then call Guildford Data Recovery on 01483 901310; imaged under per-sector timeouts, directories rebuilt from their surviving copies, files checked by opening.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.