Call us — 0161 871 0788
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
Samsung · SSD range

On a Samsung SSD, encryption is the first question.

Many of these encrypt at rest by default, often with BitLocker layered on top, and that decides whether recovery is possible before anything technical begins. It is established at the diagnostic rather than discovered after a bill.

970, 980 & SATA EVO
T5/T7 encryption
From £300 +VAT
// the short version

Quick, sealed, usually encrypted.

Samsung makes the controller, the firmware and the flash, so everything must be reached through its own stack. What decides most of these jobs is not the hardware but whether encryption sits between you and the result.

V-NAND
Samsung flash
Default
T-series encryption
48 hr
Free diagnostic
£300
From, +VAT
×Don’t run a firmware update on a Samsung SSD that has started misbehaving, and don’t secure-erase it. An update rewrites the service area that a recovery needs to read, and a secure erase is irreversible by design. If the drive is dropping out or reporting oddly, stop using it.
// encryption, before anything else

Class 0 and TCG Opal, enabled by default.

The thing that most often ends a Samsung job, and it is worth checking yourself first.

Samsung SSDs widely support hardware encryption — Class 0, which encrypts at rest with a key held in the controller and no password required, and TCG Opal, which adds an authentication layer. Portable T-series drives encrypt as standard.

Class 0 alone is not usually an obstacle, because the controller holds the key and decrypts transparently. What ends jobs is a user-set password, or BitLocker running on top — and on Windows, BitLocker may have been using the drive’s own hardware encryption without anyone realising, in which case the recovery key matters as much as it would on any encrypted volume.

Check for that key before doing anything else. On a work machine it is very likely escrowed in Azure AD or Intune and retrievable by IT in minutes. Where it is genuinely gone we can attempt password recovery, which succeeds on weak, reused or partly-remembered passwords and fails against a long random one.

// what fails

Controller first, flash rarely.

The distribution of faults across these drives.

Controller and firmware

The commonest serious failure by a wide margin. Gone from the BIOS, a blank model string, or an absurd capacity. The flash behind it is usually intact.

Most likely

Power-loss corruption

Consumer models mostly lack power-loss protection capacitors. An abrupt cut mid-write leaves mapping tables inconsistent, and the drive refuses to present rather than serve data it cannot vouch for.

Recoverable

Thermal on NVMe models

970 and 980 series drives run hot in thin laptops and under graphics cards. Often intermittent first — working cold, vanishing warm — which is a useful warning if anyone notices it.

Warning sign

Genuine V-NAND wear

Real cell degradation. Less common than people assume, and the case where prospects are weakest.

Rarest
// do not run Magician on a failing drive

Diagnostics are fine. The rest is not.

Manufacturer tooling is helpful before a problem and risky during one.

Samsung Magician is genuinely useful for monitoring a healthy drive — wear, temperature and firmware currency are all worth watching. Where a drive has already started misbehaving, several of its functions are the wrong move.

Firmware updates rewrite the service area, which is the exact region a recovery needs to read to reach the mapping tables. On a drive already in a fallback state, an update can fail partway and make the condition permanent. Secure Erase and PSID Revert are worse — the second cryptographically erases the drive by design, and it is offered as a way to regain access to a locked device.

Keep firmware current as preventative maintenance on drives that are working. Do not reach for it once one has started behaving strangely.

// what the fallback states mean

1MB, 8MB, or a blank model.

Alarming to see and better news than they look.

No drive is manufactured at one megabyte. When a BIOS reports 1MB, 2MB or 8MB, the controller is presenting a deliberate placeholder because it cannot load its own firmware or its translation tables — it has stopped serving user data rather than serving something it cannot vouch for.

These are reached through the manufacturer’s diagnostic mode, which bypasses the normal interface and allows the service area and translation tables to be read directly. Those tables are the whole job: without them the NAND is undifferentiated data, because wear levelling means the physical layout bears no relation to the logical one.

Removing the flash packages directly is a last resort rather than a first move — slower, riskier, and on encrypted drives it returns a perfect copy of something unreadable. SSD and NVMe recovery in Manchester is from £300 +VAT after a free 48-hour diagnostic.

// questions

Your questions, answered.

Frequently. The commonest serious fault is the controller rather than the flash, so the NAND still holds your data behind a layer that stopped answering — and it can often be reached in the manufacturer’s diagnostic mode.

Class 0 usually does not, because the controller holds the key and decrypts transparently. What ends jobs is a user-set password or BitLocker on top — check for the recovery key first, since on a work machine it is very likely escrowed with IT.

Its monitoring is fine; its repair functions are not. Firmware updates rewrite the service area a recovery needs to read, and PSID Revert cryptographically erases the drive by design. Neither should be used once a drive is misbehaving.

That the controller is in a deliberate fallback state because it cannot load its firmware or mapping tables. No drive is that size — it is a placeholder, and the flash behind it is usually intact.

Thermal, and it is a useful warning while it is still intermittent. Copy your data off now — a drive that vanishes warm and returns cold is telling you what is coming.

From £300 plus VAT after a free 48-hour diagnostic, with a 50% deposit for controller-level work. If the diagnostic finds the data is unreachable — encrypted without a key, or TRIMmed — you are told then.