Data Recovery Guide 2026, Turkey
What to do for physical and logical damage on HDD, SSD, RAID, NAS, phones and flash memory. An ISO/IEC 27037 compliant process, a 99.4% success rate, free diagnostics. Why the first 5 minutes after a drive dies are critical.
Data Recovery Guide 2026, Turkey
TL;DR: Data recovery is the work of retrieving files from storage devices (HDD, SSD, RAID, NAS, phones, flash memory) that have become inaccessible either physically or logically. Software cases are resolved within hours, while physically damaged drives are handled in a cleanroom within 3 to 14 days. With the right team, the success rate stays high (DSET 99.4%). First rule: power the device off, do not turn it back on, do not follow "fix it yourself" videos, bring it to an expert.
The drive died, what should you do in the first 5 minutes?
The drive has started clicking, the phone will not turn on, the NAS says "drive failed." Do not panic. What you do in the first half hour largely determines whether the data comes back or not. The wrong move doubles the extent of the damage.
Here is what you need to do, in order:
- Power the device off immediately. If a mechanical HDD is clicking, every second the head continues to scrape the platter, and the recoverable area shrinks. Pull the power cable.
- Do not keep turning it on and off. Do not say, "Maybe it will boot this time." Every power cycle stresses the controller and the platter. On SSDs, the controller locks up completely.
- Do not install data recovery software. Installing tools like Recuva, EaseUS or R-Studio on the damaged drive is the most common mistake. The software overwrites the area you are trying to recover.
- Do not run CHKDSK, fsck or "repair disk." NEVER say yes to Windows' "there is a disk error, shall I repair it?" message. Repair rewrites the file table and you can lose the data permanently.
- Do not freeze, hit or shake the drive. These myths circulating on forums are left over from the 2000s. On a modern drive they make the physical damage worse.
- Do not try to dry it after water or liquid contact. No hair dryer, no bag of rice, no sun. Once it dries, corrosion begins. Bring it to the lab while still wet, in an anti-static bag.
- If it is a phone, do not try a factory reset. A factory reset done in the hope that "maybe it will fix itself" empties the NAND cells with the TRIM command and erases the data irreversibly.
In short: power the device off, do not touch it, bring it to a lab that works in compliance with ISO/IEC 27037.
What is data recovery?
Data recovery is the process of retrieving files with specialized hardware and software in cases where a storage device has become inaccessible through the normal operating system. The principle DSET has followed since 2003 is clear: We care about your data. The work is performed not on the original media but on a bit-level, one-to-one clone (forensic image). This is the standard approach, also aligned with NIST SP 800-86.
There are two main damage categories in the industry:
Logical damage. The drive is physically intact, but the file system, partition table, MBR/GPT or bootloader is corrupted. Accidental deletion, formatting, ransomware encryption, viruses and OS crashes fall into this category. The fix is usually software-based, fast and relatively inexpensive.
Physical damage. There is a tangible fault in the drive's hardware. On an HDD, the read head may be crashed, the motor seized, the platter scratched, or the PCB burned out. On an SSD, the controller chip may be dead, the NAND degraded, or the firmware corrupt. These cases require an ISO 14644-1 Class 100 cleanroom, PC-3000, a DeepSpar Disk Imager and a stock of donor parts.
Device categories within the scope of data recovery:
- HDD (3.5" desktop, 2.5" laptop, helium-filled enterprise drives)
- SSD and NVMe (SATA, M.2, U.2, mSATA)
- RAID arrays (hardware controller, software RAID, hybrid)
- NAS devices (Synology, QNAP, Drobo, Asustor, Buffalo)
- Mobile devices (iOS, Android, legacy Windows Phone)
- USB sticks, SD and microSD, CompactFlash
- Magnetic tape (LTO 4-9), legacy floppy and ZIP media
- Virtual disk images (VMDK, VHDX, QCOW2)
- Database files (SQL, Exchange, Oracle DBF)
The process shares the same discipline as digital forensics: chain of custody is preserved, every step is logged, and integrity is verified with hashes.
Which devices can data be recovered from?
HDD (Mechanical Hard Disk)
Mechanical drives are still the backbone of the backup and archive market. Failure symptoms: a "click click" sound (head crash), the motor not spinning (stiction or a seized motor bearing), not appearing in the BIOS (corrupt firmware), strange slowness (an accumulation of bad sectors). When the Reallocated Sector Count and Current Pending Sector values in the S.M.A.R.T. data climb, the drive is in its final days.
Mechanical intervention requires a cleanroom. A speck of dust the thickness of a strand of hair landing on the platter causes a head crash. In DSET's lab, PC-3000 Express and DeepSpar are used for imaging, bad sectors are dumped with retry strategies, and donor PCBs and donor head stacks are matched. If the platter is scratched, a surface map is generated and partial data recovery is performed from the intact tracks.
SSD and NVMe
Recovering an SSD is technically harder than an HDD. A single controller chip, plus layers of encryption, wear leveling and garbage collection, get in the way. When the controller dies, the data on the NAND chips remains "encrypted" and you cannot read it without the correct key. JEDEC standards (JESD218, JESD219) define endurance and TBW (Total Bytes Written) limits; consumer SSDs typically endure 150-600 TBW, after which they gradually shift to read-only mode.
Data recovery routes: vendor-specific service mode (the proprietary service commands of Samsung, Crucial, Kingston and SanDisk), chip-off (desoldering the NAND and placing it in a programmer), and firmware bypass with PC-3000 SSD. If TRIM has run, the vast majority of deleted files have been physically wiped from the NAND, and there is no way back. That is why the less time that has passed since the moment of "deletion," the better the odds.
RAID (5, 6, 10, 50)
RAID recovery is a different discipline from a single drive: first each member disk is cloned, then the stripe size, disk order, parity rotation and offset are determined and the array is virtually rebuilt. In RAID 5, if two disks went down at the same time or the second disk died during a rebuild, the classic array shuts down completely, but partial recovery from each disk's image is possible. RAID 6 tolerates the loss of up to three disks, RAID 10 one disk per stripe.
NAS brands like Synology, QNAP, Drobo and Asustor add a proprietary layer on top. Synology Hybrid RAID (SHR), Drobo BeyondRAID, Btrfs and ZFS RAID-Z each require separate re-assembly logic. Classic data recovery software cannot read these. If the NAS firmware, even in a failed state, prompts you to "init" the disks, do not go through with it. Remove the disks, label them, and bring them to the lab in the same order.
Phones (iOS / Android)
Mobile data recovery is the gray zone of digital forensics. Forensic tools like Cellebrite UFED, Magnet AXIOM and Oxygen Forensic Detective are also used in everyday data recovery cases. If an iPhone has a cracked screen, a logical extraction over Lightning/USB-C is mostly possible depending on its power state. If there is an encrypted iOS backup, direct access from the iTunes/Finder backup is available.
The Android side is fragmented. Samsung Exynos, Qualcomm and MediaTek use different bootloaders and EDL/Download mode commands. On encrypted Android 10+ phones, data cannot be extracted without the user password, as it is tied to the hardware key. If the phone has not been factory reset there is a chance; if it has, the data is mostly gone due to TRIM. If there is an iCloud/Google Drive backup, recovering via the cloud is the most reliable route.
Flash, USB, SD Card
Wear leveling is more aggressive on USB sticks and SD cards, and the NAND cells age quickly. Typical failures: a broken connector, controller chip death, NAND degradation. If the connector is broken, repair with micro-soldering is easy. If the controller has died, chip-off is mandatory: you desolder the NAND, place it in a programmer, take a raw dump, then engineers reverse engineer the XOR/scrambling and ECC that the controller applied. On microSD cards, the monolithic design requires silicon-level prep (decapping with acid, micro wire bonding). The cost is high and success varies by case.
After ransomware
On a ransomware-infected system, first control the panic: disconnect the computer from the network, do not shut it down, take a photo of the screen, save the ransom note. Check via USOM and the No More Ransom Project whether a decryptor exists for the family. Decryption is possible for the offline IDs of some variants such as STOP/Djvu, GandCrab, Maze and REvil. If the Volume Shadow Copy has not been deleted, an earlier version can be restored with vssadmin list shadows.
Important: do not pay the ransom. Payment does not guarantee 100% that the key will arrive, and it funds the next attack. If you fall under KVKK, since this is a personal data breach you are required to notify the KVKK Authority within 72 hours. CISA and ENISA publish the international guidance for this process.
The data recovery process, step by step
Every case in the DSET lab goes through the same disciplined process. ISO/IEC 27037 and NIST SP 800-86 are taken as reference, and the chain of custody is documented.
- Diagnosis and free assessment. The device is received, a physical inspection is carried out, and S.M.A.R.T. is logged if it can be read. Whether the case is logical or physical becomes clear at this stage. The customer is presented with a damage report and a process plan, and the price is finalized. No payment is taken at this stage.
- Taking a forensic image (clone). The original media is never touched again. All work is done on the one-to-one image. On drives with bad sectors, multiple retry passes are made with DeepSpar or PC-3000, and a sector map is generated. The SHA-256 hash is recorded.
- Structure analysis. If it is a RAID, the stripe, order and parity are determined. If there is an encrypted volume (BitLocker, FileVault, LUKS, VeraCrypt), the key/password is requested. The file system is parsed (NTFS, ext4, APFS, HFS+, exFAT, Btrfs, ZFS).
- Data extraction (carving). First a rebuild is done preserving the directory structure. If the structure is corrupted, extraction by file type is performed with file signature carving (R-Studio, PhotoRec, X-Ways).
- Verification. The recovered files are opened and tested. Corrupted files are separated into a separate folder. Dedicated validators are run for formats like JPG, MP4, DOCX, PST and MDF.
- Delivery. The data is delivered to the customer on a new disk or in an encrypted folder. A list report is provided.
- Confidential destruction. With the customer's approval, the working copies and images are wiped at the NIST SP 800-88 Purge level, and a hashed destruction record is provided.
What determines the success rate?
Four factors determine success in data recovery. The first is device type: SSD and modern NVMe show lower recoverability than mechanical HDDs because TRIM and hardware encryption get in the way. With RAID it depends on the parity and the number of disks; RAID 6 withstands the loss of up to three disks.
The second is the date of damage. With liquid contact, the first 24 hours are critical, as corrosion advances rapidly. For a deleted file, there is still a chance even months later on a non-TRIM HDD, whereas on a TRIM-enabled SSD the area can be cleared within minutes.
The third is what was done before intervention. The wrong move by the user or another service (CHKDSK, format, "turning on and off," a cheap soldering repair) lowers success. Cases that come in saying "we tried elsewhere first, it did not work" are always harder.
The fourth is the quality of equipment and expertise. Industry-standard devices like PC-3000, DeepSpar and Atola Insight, an ISO 14644 cleanroom, a donor stock, vendor-specific firmware knowledge, experience. The 99.4% success rate and 20,000+ TB of recovered data figures that DSET openly shares rest on this infrastructure. Within the frame of 20+ years of experience, 100+ corporate clients and 1,350+ academy graduates accumulated since 2003, they are frequently cited in the industry.
Why does the cost of data recovery vary?
There is no fixed price list in data recovery, nor is there one across the industry. The reason is that every case is unique: of two HDDs of the same model, one comes in with a head crash and the other with just a cluster of bad sectors. The cost of the second is one tenth of the first.
The main factors that determine cost:
- Type of damage. Software (logical) cases are the most affordable. Physical mechanical is the highest. Chip-off and silicon-level intervention are the highest tier.
- Device type and capacity. There is a difference between a consumer HDD and an enterprise helium drive or NVMe. As capacity increases, the imaging time grows.
- Cleanroom requirement. Head, motor and platter intervention require an ISO Class 100 environment. It is a high hourly-cost resource.
- Donor parts. Sourcing the same model PCB, head stack or motor sometimes depends on the market.
- Urgency. Standard queue, or 24/7 priority intervention.
DSET's workflow is as follows: a free assessment is done first, the device is inspected, a damage report is produced, and you are told a clear price and turnaround time. If you approve, work begins. If no data is recovered, no fee is charged. This "no data, no fee" principle is a trust policy that has become standard across the industry.
Confidentiality and KVKK
Devices within the scope of data recovery mostly contain sensitive content such as personal data, trade secrets, financial statements, customer records and patient files. KVKK and, on the European side, GDPR obligations begin here.
The standard DSET applies: a mutual NDA is signed with the customer, access from the device's entry to its exit is open only to the assigned expert, the work is done in a closed-circuit lab, and there is no external network connection. Customer data never leaves the country under any circumstances, is not transferred to a third country, and stays within the Hacettepe Teknokent physical security perimeter. After the work is complete, with the customer's approval, the working copies are wiped at the NIST SP 800-88 Purge level with multiple-pass overwrite, and a hashed destruction record is signed. For corporate clients, an ISO/IEC 27037 compliant forensic report can additionally be prepared, and a chain of custody document is provided in cases requiring court evidence.
Frequently Asked Questions (FAQ)
How long does data recovery take on average?
Software cases (deletion, format, partition loss) usually finish in anywhere from a few hours to 1 business day. Physically damaged drives take 3 to 7 business days. Heavy mechanical cases requiring a cleanroom and chip-off work can take 1 to 2 weeks. In RAID arrays, depending on the number of disks and the capacity, the imaging alone can take a few days.
Do you charge if you cannot recover the data?
No. If no data is recovered, no fee is charged. A free assessment is done first, a damage report is produced, and a clear price is given. Work does not begin without your approval. This principle is known in the industry as "no data, no fee" and is DSET's standard policy.
Which types of RAID configurations can be solved?
RAID 0, 1, 5, 6, 10, 50, 60, JBOD, span. In addition, the proprietary formats of NAS brands: Synology Hybrid RAID (SHR and SHR-2), Drobo BeyondRAID, Netgear X-RAID, Buffalo TeraStation native. On the software RAID side, Btrfs RAID 1/5/6, ZFS RAID-Z1/Z2/Z3, mdadm, Storage Spaces, Apple Fusion Drive and macOS Software RAID are supported.
My phone screen is cracked, can the data be recovered?
In most cases, yes. If the phone can still turn on and the password is known, logical extraction over USB is easy. If it will not turn on, the data interface is revived by fitting a service screen, then extraction is performed. If the motherboard is burned out, chip-off and JTAG/ISP methods come into play. On an iPhone there is no bypass without the user password, but if there is an iCloud backup, a full restore via the cloud is possible.
Can it be used as evidence in court?
Yes, but for that the process must be carried out from the start in line with digital forensics discipline. Recovery reports produced from an image that is ISO/IEC 27037 compliant, with a documented chain of custody, hash verification and taken with a write-blocker are accepted as evidence in Turkish courts. If the device may become the subject of a lawsuit, it is more sound to handle it from the very start as a "digital forensics examination" rather than "data recovery."
Can a drive that has been underwater be recovered?
Yes, but do not try to dry it. A bag of rice, a hair dryer, the sun, none of them work and they accelerate corrosion. While the drive is wet, put it in an anti-static bag or a plastic container with a lid, drop in 1-2 silica gel packets, and bring it to the lab immediately. In the cleanroom the PCB is removed, the platters are cleaned with an ultrasonic bath and isopropyl alcohol, and an image is taken with a donor stack.
What is the data recovery guarantee like?
The guarantee rests on four foundations: first, the original media is never touched, all work is done on the clone, and if something goes wrong you still have the original. Second, at every critical step a SHA-256 hash is taken and integrity is verified. Third, confidentiality within the frame of an NDA. Fourth, a hashed destruction record once the work is done. The recovered files are delivered to you as a list, and a working copy is kept until you approve.
Who not to recover data with
The data recovery market is full of people saying "we will recover it in 5 minutes." Services that promise cheap, give no guarantee, open an HDD even though they have no cleanroom, and do not share photos of their equipment are the biggest risk. The wrong move can make a later professional recovery impossible.
Things to avoid:
- The phone shop, computer shop or mall repairman who says "let me open it right away and take a look." When a mechanical HDD is opened outside a cleanroom, dust sticks to the platter and a head crash begins.
- Forums that suggest putting the drive in the freezer. An urban legend of the 2000s, it directly destroys a modern drive.
- The cheap service that says "let's swap the PCB." Modern HDDs have an adaptive ROM on the PCB, and swapping it out without transferring the correct BIOS region burns out the motor or the head.
- Those who say "let's pull the data first, then talk" with no guarantee. There should be a written price and turnaround time first.
- Those who say they use customer data for test/demo purposes. It is a KVKK violation.
- Those who process the device in a network-connected lab. An air gap is mandatory.
The right service: shares a photo of the cleanroom, names industry-standard equipment like PC-3000/DeepSpar/Atola, signs an NDA, offers a free assessment, works on the "no data, no fee" principle, and issues a KVKK compliant destruction record.
Working with DSET
DSET has worked in data recovery and cybersecurity since 2003, at Hacettepe Teknokent, Çankaya, Ankara. 20+ years of experience, 20,000+ TB of recovered data, 100+ corporate clients, 1,350+ academy graduates and a 99.4% success rate.
Contact:
- Phone (24/7 emergency response): +90 536 662 38 09
- Email: [email protected]
- Free assessment: bring the device, get a damage report and a clear price, and you make the decision.
- ISO/IEC 27037 compliant report, NDA, KVKK compliant destruction record, hash-verified delivery.
- Corporate SLA, digital forensics expertise, and a chain of custody document in cases where evidence will be presented in court.
We care about your data, we are waiting for you at Hacettepe Teknokent.
Sources:
- NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response
- NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization
- ISO/IEC 27037, Digital Evidence Identification, Collection, Acquisition and Preservation
- ISO 14644-1, Cleanroom Classification
- JEDEC SSD Specifications (JESD218, JESD219)
- S.M.A.R.T. Attributes Reference
- KVKK, 72-hour breach notification
- USOM, Turkey National Cyber Incident Response Center
- BTK, Information and Communication Technologies Authority
- ENISA, EU Agency for Cybersecurity
- CISA, Cybersecurity and Infrastructure Security Agency
- No More Ransom Project
Related In-Depth Articles
- GoPro, Drone and Dashcam microSD Video Recovery: Why Do Fragmented 4K Videos Open Corrupted?
- Recovering Data from a Broken Android Phone That Will Not Turn On: ISP, Chip-Off and the Encryption Barrier
- Mac APFS and Fusion Drive Data Recovery: Snapshot, FileVault and the SSD+HDD Split
- Can Files Encrypted by Ransomware Be Recovered? The Honest Truth
- Outlook PST/OST Email File Corrupted: Why It Happens and How to Recover It
- SQL Server and MySQL Database Recovery: MDF, InnoDB and Suspect Mode
- VeraCrypt Encrypted Container Corrupted: Header, Password and the Limits of Recovery
- eMMC and UFS Embedded Storage Data Recovery: Phone, Tablet and BGA Soldering
Related Solutions and Services
Go to the right page for the device where you lost data:
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.