CounterfeitJune 27, 2026

Counterfeit SSDs in Servers: How They Affect Company Data

The drive shows 1.92 TB, but inside are chips reflashed to report 480 GB. How SSD capacity fraud works, why RAID doesn't save you, and four tests that catch it before data loss.

The drive shows 1.92 TB in the system. In reality, a reflashed controller uses 480 GB worth of memory chips and cyclically overwrites the same physical block, reporting a fictitious capacity to the system. The moment your actual data volume exceeds the real physical capacity, new writes start overwriting old ones — no error, no warning, part of your data simply disappears. This isn't theoretical — it's the most common SSD counterfeiting scheme on the market.

How Controller Reflashing Works

Counterfeit SSDs usually aren't entirely "empty" shells with no memory at all — inside are genuine, but cheaper and lower-capacity, NAND chips. The controller firmware is modified so the operating system sees the claimed larger capacity (e.g., 1.92 TB instead of an actual 480 GB). This is achieved through cyclic addressing: once writes reach the real memory limit, the controller transparently redirects new data to already-occupied physical cells, overwriting whatever was there.

To the user, the drive appears to work normally — right up until the volume of data actually written exceeds the physical capacity. After that, silent data loss begins with no obvious sign of failure.

Why This Is Especially Dangerous for Servers and Databases

  • No explicit write error. The controller doesn't return an error code — it simply overwrites old data while simulating a successful operation
  • RAID arrays don't protect against this threat. If every drive in the array is counterfeit, the problem hits all of them synchronously — RAID 5/10 doesn't save you from logical data loss happening at the controller level
  • Backups can capture already-corrupted data. If the loss is gradual and unnoticed, regular backups will preserve the corrupted version of files before the problem is ever discovered
  • Reduced real write speed goes unnoticed in basic tests. Fakes often show normal speed on short benchmarks but degrade under the sustained load typical of databases and virtualization

Four Checks Before Putting an SSD into Service

  1. Full write-and-read test of the entire claimed capacity. Tools like H2testw or F3 write data across the whole drive and verify integrity on read — a faked capacity is exposed immediately if real memory falls short of the claim
  2. Read the full SMART log. Model, firmware, claimed User Capacity, and Total Bytes Written fields should be internally consistent. Fakes often show atypical or unreadable manufacturer fields
  3. Compare weight and physical dimensions. Fewer NAND chips inside is sometimes noticeable in the drive's weight relative to the claimed model — a discrepancy of more than 20% from spec is grounds for further checking
  4. Check the serial number on the manufacturer's site. Samsung, Kioxia, Western Digital, and Seagate all offer warranty lookup tools by serial number — a mismatch or missing record indicates a fake

Where Counterfeit SSDs Show Up Most Often

The highest risk is in drives bought outside an authorized distributor: marketplaces, private sellers, intermediaries without official status. Inside a new server from an authorized Dell or HPE partner, the risk is minimal — drives ship from the vendor with their own authenticity verification at the assembly stage. Risk rises sharply when buying drives separately as "compatible with" a specific server — especially if the price is noticeably below official list.

What to Do If a Fake Is Found After Installation

  • Stop writing new data to the drive immediately — continued use increases the volume of potentially lost information
  • Copy all data to a verified drive, starting with the most critical files
  • Document the test results (H2testw/F3) and SMART log as evidence for a supplier claim
  • Don't attempt to "reflash it back" yourself — this can accelerate the loss of remaining data

Checklist Before Buying SSD/NVMe Drives for a Server

  • ☐ Drive purchased from an authorized Dell/HPE or SSD manufacturer distributor
  • ☐ Serial number checked on the manufacturer's site (Samsung, Kioxia, WD, Seagate)
  • ☐ Full write/read test of claimed capacity performed before production use
  • ☐ SMART log read and checked for internal consistency
  • ☐ Price not below 60-70% of the official list for the same model

If you need drives with guaranteed authenticity for server infrastructure — contact us. We supply genuine SSD/NVMe drives as part of certified Dell and HPE configurations.

Frequently Asked Questions

Can a fake be detected without specialized software?

Partially: drive weight and SMART data give early signals, but precisely exposing a reflashed capacity requires a full write/read test with a dedicated tool (H2testw, F3).

Does RAID protect against data loss on a counterfeit SSD?

No, if every drive in the array is counterfeit — the problem hits each one synchronously, and RAID can't recover data physically overwritten at the controller level.

How long does a full test of a 2 TB drive take?

Depending on interface speed — from a few hours for a SATA SSD to 1-2 hours for NVMe. It pays for itself compared to the risk of silent data loss.

Does this issue affect HDDs too, or only SSDs?

Yes, the same controller-reflashing scheme applies to hard drives as well, though it's more common with SSD/NVMe on the server market due to the higher margin on the fake.

Need IT equipment?

Derzhava-E — authorized Dell and HPE supplier in Kazakhstan. Free consultation.

Get a quote
← Back to blog