Call us — 0161 871 0788
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Cameras, Drones & Cards · The Copy Was a Move

A Transfer Stopped by a Full Destination Should Not Have Removed Anything

Her enquiry describes a loss on the wrong side of the operation. A card holding a full 32GB of photographs where "during download the computer ran out of space so the download was halted, and the remaining photos on the card are now hidden" — with only 5GB still visible. A copy that fails for lack of destination space does not touch the source, which means something other than a copy was happening.

Media32GB compact flash card substantially occupied — transfer to a computer halted by insufficient destination space; approximately 5GB of content remaining visible
Reported situationMemory card substantially full of photographs · transfer to a computer commenced · destination running out of space during the transfer · transfer halted · approximately 5GB of photographs remaining visible on the card · remaining content no longer listed · recovery sought
Fault classSource entries removed during an interrupted transfer — move semantics or directory update indicated; content retained pending overwriting
Equipment usedSource-side loss assessed as move semantics rather than copy failure · card removed from use before assessment · imaged write-blocked before any scanning · signature carving performed across the whole card independently of directory entries · destination examined for content transferred before the halt

The decode: what removed the entries, and why the photographs remain

Why a copy could not have caused this: copying reads the source and writes the destination. It has no reason to modify the card at all, so a copy failing for lack of space leaves the card exactly as it was.

What therefore must have been happening: a move rather than a copy. A move copies each file and then deletes the original, working through the set one at a time — so an interruption partway leaves the transferred portion deleted from the source.

Why that fits her account precisely: the visible 5GB is what had not yet been reached. The photographs that vanished are the ones that were successfully copied and then removed, in the order the operation processed them.

Why she may not have chosen a move deliberately: some import tools offer to remove items after importing, occasionally as a default. The option is easy to enable once and forget, and it behaves invisibly until something interrupts it.

Why the destination is the first place to look: those files were copied before being deleted. Everything removed from the card should have arrived on the computer, and the loss may be smaller than it appears.

Why that must be checked rather than assumed: a move deletes after a copy it believes succeeded. If the destination ran out of space mid-file, the last one may have been deleted from the card while arriving incomplete — which is the one genuine casualty of this pattern.

Why the deleted photographs are still recoverable from the card: deletion removes the entry and marks the space available. The images remain where they were written until something overwrites them, and nothing has been written to the card since.

Why the card must come out of use immediately: that is the only variable left. Any further use writes into precisely the space the deleted photographs occupy.

Why compact flash of this kind carves reliably: photographs carry recognisable openings, and the card was filled sequentially by a camera. Deleted images sit in long contiguous runs rather than scattered.

What is worth doing before anything else: freeing space on the computer and checking what actually arrived. If most of it is there, this becomes a much smaller job — and that costs nothing to establish.

On the bench

Source-side loss was assessed as move semantics rather than copy failure — copying reading the source and writing the destination without modifying the source, so a copy halted by insufficient space leaves a card unchanged, whereas a move copies each file then deletes the original in sequence, leaving the transferred portion removed when interrupted. Visible content corresponds to files not yet reached. Carving was performed across the whole card independently of directory entries.

The outcome

Source-side loss assessed as move semantics, the card removed from use and imaged, and the destination examined for content transferred before the halt. Free assessment, one fixed written figure including VAT; on cards where content has been deleted, the figure is payable upfront. The decode: a copy could not have done this, because copying does not modify the source. What ran was a move — copy each file, then delete it — so the photographs that vanished are the ones that were already transferred.

When a transfer stops and the source loses files too

Check the destination first and free some space there, because everything removed from your card should have arrived on the computer before being deleted — the loss may be far smaller than it looks. What happened is a move rather than a copy: copying only reads the source, while a move copies each file and then deletes the original one at a time, so an interruption leaves the transferred portion gone from the source. Some import tools offer to remove items after importing, sometimes as a default. Take the card out of use now, since nothing has overwritten those images yet.

Transfer halted and files missing from the card too?
Check what arrived first — call Manchester Data Recovery on 0161 871 0788; source-side loss assessed as move semantics, imaged before scanning, carving performed independently of directory entries.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.