Recruiting teams still run a surprising amount of hiring work in Excel. Even when an applicant tracking system is in place, sourcers and hiring managers often keep offline workbooks for candidate pipelines, interview scorecards, reference notes, agency submissions, and salary or equity planning. Those files can contain names, phone numbers, email addresses, salary expectations, and interview feedback, so people naturally protect them with a password.
The problem begins when that password lives in one person's head. A recruiter leaves, a shared drive is migrated, or a workbook copied from an old project simply will not open. This guide explains how to diagnose the lock, what to try before attempting recovery, and how to approach encrypted .xlsx and .xls files without exposing candidate data.
Identify Which Kind of Lock You Are Facing
Excel uses the word "password" for two very different controls, and treating them as the same problem wastes time.
| Symptom | What is actually happening | Security level |
|---|---|---|
| Excel asks for a password before the workbook will open at all | File-level encryption with an open password | Strong; modern .xlsx files use AES encryption |
| The file opens, but cells, tabs, or structure cannot be edited | Worksheet or workbook protection | Weak; designed to prevent accidental changes, not protect secrets |
| The workbook opens in read-only mode and asks for a password to edit | A modify/read-only restriction, sometimes combined with encryption | Moderate; depends on how the file was saved |
If you can see candidate data on screen but cannot change a tab or unhide columns, you are probably dealing with sheet protection rather than encryption. That is usually an administration problem, not a cryptographic one. If Excel refuses to open the file without the correct password, the data is genuinely encrypted and recovery has to work against the encryption.
Try the Low-Risk Steps First
Before running any recovery job, work through these checks. They are free, non-destructive, and resolve a surprising number of lockouts.
- Work from a copy. Copy the workbook to a separate folder before doing anything. Keep the original untouched.
- Check the shared password vault. Look in the team password manager for entries tied to the recruiter, requisition, agency, or hiring manager. Old entries are often stored under project names rather than file names.
- Check version history and backups. OneDrive, SharePoint, Google Drive (if the file was uploaded there), NAS snapshots, and IT backups may contain an older copy saved before encryption was added.
- Ask the former owner through the proper channel. During offboarding, the previous recruiter or coordinator may be able to share the password with IT or people operations. Have the recipient store it immediately in the team vault.
- Build a short, intelligent candidate list. Consider company names, office locations, requisition numbers, project nicknames, years, and common suffixes. Keep this list short and targeted. Guessing hundreds of variants manually is not realistic against strong encryption, but pattern clues are valuable later.
- Export from the system of record. If the workbook was a recruiting tracker, the ATS may still hold most of the candidate names, statuses, and interview feedback. Re-exporting can be faster than recovery for everything except unique notes.
Why a Modern Encrypted .xlsx Is Hard to Unlock
When a current Excel workbook is saved with an open password, the password is not stored in the file. Instead, Excel stores verification data derived from the password, and recent Office versions use AES-256 encryption with strong key derivation. Every candidate password has to be mathematically tested against that verification data.
Several factors determine how feasible that is:
- Password length: each extra character multiplies the search space.
- Character variety: lowercase words alone are far easier than mixed letters, digits, and symbols.
- Known patterns: a remembered prefix, base word, year range, or minimum length dramatically shrinks the job.
- Excel version: older .xls files and older Office encryption are generally faster to attack than current .xlsx encryption.
- Computing power: a laptop CPU is usually too slow for complex jobs; GPU-based testing can evaluate candidates far more quickly.
No legitimate service can honestly promise an instant or guaranteed bypass for strong AES encryption. The realistic question is whether the password falls within a search space that can be tested with available time and computing power.
Practical Recovery Options
Option 1: Structured self-recovery
If you have technical expertise, you can extract the encryption verification data from a copy of the workbook and test passwords with a dictionary or mask configuration. A mask uses what you remember—for example, a company prefix followed by four digits—instead of testing every possible combination.
This route can work for simple passwords, but current Office encryption is deliberately slow per attempt. Running the job on a standard laptop can take days or weeks, and configuring masks correctly requires some familiarity with the tools.
Option 2: GPU-assisted recovery with a privacy-first service
For long or complex passwords, a GPU-backed service is often the more practical route. Catpasswd focuses on encrypted file recovery and supports password-protected Excel workbooks without requiring the original spreadsheet to be uploaded. A small hash/verifier can be extracted locally, so candidate names, contact details, and interview notes remain on your machine.
The service tests candidate passwords against that extracted data using cloud GPU resources, combined with a larger dictionary and password-pattern database than most teams maintain locally. In the free mode, after a password is found you can wait to view it at no charge; a paid option reveals it immediately. If the recovery attempt is unsuccessful, there is no charge for the job.
Providing whatever you remember is important: approximate length, whether it used a company or project word, likely digits or years, and capitalization patterns. Better clues turn an impractical search into a targeted one.
Option 3: Rebuild from source systems
Sometimes the fastest answer is not recovery. If the locked workbook mainly lists candidates and statuses, re-export from the ATS, reconcile offer data from HRIS records, and ask interviewers for their scorecards. Reserve the recovery job for files containing unique information that exists nowhere else, such as compensation modeling or confidential reference notes.
Protect Candidate Privacy During the Process
Recruiting files are not ordinary spreadsheets. They often contain personal data subject to employment and privacy rules, as well as internal obligations around pay equity and hiring decisions.
- Avoid generic "upload your file here" unlock websites. Sending a complete candidate tracker to an unknown service can expose personal data and may violate internal policy or applicable privacy law.
- Prefer a local hash-extraction approach so the full file never leaves your environment.
- Only recover files your organization owns or is authorized to access. If the workbook belonged to a former recruiter, involve IT, HR, or legal early and document the authorization.
- Be skeptical of services advertising guaranteed results or claiming to break AES encryption immediately.
After You Regain Access
Once the workbook opens, reduce the chance of another lockout:
- Save a decrypted master copy in a secured SharePoint, OneDrive, or approved team folder controlled by group permissions rather than a shared password.
- If a password must remain on a specific copy, store it in the shared team vault with a named owner and backup owner.
- Use worksheet protection only as a guard against accidental edits; never treat it as confidentiality for salary or candidate data.
- Move the tracking process into the ATS or a properly governed spreadsheet template, and limit offline copies containing personal data.
- Add "shared workbooks, vault entries, and external recruiter files" to the offboarding checklist so passwords are recovered before access is lost.
Frequently Asked Questions
I can open the spreadsheet but cannot edit cells. Is it encrypted?
No. If the data is visible, you are likely facing worksheet or workbook protection, which is meant to prevent accidental changes. That is much easier for an authorized IT or spreadsheet owner to resolve than true file encryption.
Can any service unlock an encrypted .xlsx immediately?
No honest provider can promise that for modern Excel files. Current .xlsx encryption uses strong AES key derivation, so recovery depends on the password's length, complexity, remembered patterns, and available computing power.
Do I need to upload the whole candidate spreadsheet?
Not with Catpasswd. A local hash/verifier can be extracted from the workbook and used for testing, while the full file—including candidate personal data—stays on your device.
How long does Excel password recovery take?
It can range from minutes for a simple dictionary-based password to days or longer for a long, random password. Older .xls files are generally faster than current .xlsx files, and accurate clues such as prefixes or year ranges significantly reduce the search.
Will recovery damage the workbook or its formulas?
Testing is normally performed against an extracted verification copy, so the original file is not modified. Keep the original untouched and work only from copies until the correct password is confirmed.
Is it appropriate to recover a file left by a former recruiter?
It can be, provided the organization owns the file and the request is authorized by IT, HR, or management. Document the business reason, avoid uploading personal data to unknown websites, and reset access and ownership as soon as the workbook is open.