The moment your data is locked inside a file you can no longer open, the problem stops being about spreadsheets and starts being about trust in your own work. This is exactly where u/douff and their partner have landed: a 2019 Excel file holds the raw data from her PhD, a publication needs amending, and the password that should protect that work is now the very thing keeping her out of it. They have tried the obvious paths, hunting for exports, checking old password habits, even attempting the zip-and-peek trick. None of it worked. That is not a failure of effort. It is the reality of modern encryption doing exactly what it was designed to do.
The uncomfortable truth is that a fully password-protected Excel file, especially one from 2019, is not a puzzle with a clever backdoor. When the entire workbook is locked, the encryption is applied to the file itself, not just a sheet or a range. That means the zip-and-viewer approach fails because the contents are not merely hidden, they are scrambled. And without the password, there is no metadata to peek at, no structure to infer. The only practical route left is a brute-force or dictionary attack, where software tries thousands of combinations per second until something clicks. For a determined user with a decent GPU, a password that is short, simple, or based on a known phrase from that era might fall within hours or days. If the password is long, random, or includes special characters, the math shifts dramatically. At that point, the honest answer is that the data may be unrecoverable without the original passphrase.
What makes this situation so frustrating is that it was entirely avoidable, and yet entirely understandable. Passwords from 2019 feel recent until you are staring at a lock screen and your brain refuses to retrieve a string of characters you typed without thinking four years ago. The real lesson here is not about Excel. It is about the fragility of memory as a security mechanism. For researchers, students, and anyone who stores irreplaceable data, the takeaway is blunt: if a file is important enough to protect, it is important enough to have a recovery path. That might mean a password manager, a written backup in a secure location, or a secondary copy with a different encryption scheme. It is not about being paranoid. It is about recognizing that the same security that keeps intruders out will also keep you out when you need in most.
So what should u/douff and their partner do next? Start with a targeted dictionary attack using passwords she remembers using around 2019, including variations with numbers and symbols. If that fails, consider whether the file was ever synced to a cloud service like OneDrive or Google Drive, where older versions might exist without the same lock. And if neither works, the final option is to accept the loss and rebuild the dataset from other sources, perhaps her supervisor has a copy, or the publication itself contains enough summary data to correct the record. It is a hard pill to swallow, but it is also a reminder: the tools that protect our work are only as good as our ability to access them when the password fades. Plan for that moment now, before you need it.