Security1 distinct publisher3 min readPublished
Pen Test Partners recovered a family's locked encrypted Excel file in under a minute once relatives recalled the password format. The hygiene was right; the handover did not exist.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The keyspace is where this story actually turns. A 13-character password drawn from the full printable set runs to about 5.1e25 candidates; against the rig Pen Test Partners describes, which it says sustains more than 10 billion hashes per second [7], that is on the order of 160 million years [3]. Once the family remembered that he wrote passwords as word, digit, exclamation, word [5], the same secret became a combinator run: roughly 80,000 dictionary entries decorated with a digit and an optional bang, combined against an 88,000-word list [6]. Assume one digit and the optional character, and that is about 1.4e11 candidates, near fourteen seconds of GPU time [2]. The firm reports it fell in under a minute [7].
Nothing before that recollection could have worked. The team brute-forced to nine characters and ran dictionaries with rules and family-suggested words over a weekend [4], while the answer sat four characters past the ceiling they were sweeping [1]. The password itself was not weak by construction, 13 characters with mixed character classes, and the firm's stated flaw was the two dictionary words inside it [8].
So the man did the thing every security programme asks for. Strong, unique credentials everywhere, stored encrypted [2]. The part that failed was ownership of recovery, and his family were locked out of everything [1]. The blog's author treats that as an engineering problem rather than a paperwork one, and his own arrangement is worth reading as a control specification: a named colleague, Scott, has agreed in advance to simplify the network and strip out Home Assistant, and keeps whatever he removes, with the author's passwords written down, secured and accessible to others [12]. That is a succession plan with a degradation path attached, which matters when Home Assistant is the thing controlling physical access across a 10-VLAN Ubiquiti stack, two internet connections and a Proxmox cluster [11]. A locked-out household there is a door problem, not an inconvenience.
The inversion is the uncomfortable part. The format knowledge that rescued this family is the same asset an attacker wants, and the firm's own guidance says so: memorable-format schemes are acceptable for online accounts sitting behind a lockout policy, and not for anything attackable offline or exposed in a compromised database, where length and the absence of dictionary words are what count [9]. A house style for passwords is a shared secret across every hash you have ever leaked.
This is one vendor's account of one job, and the throughput figure is self-reported [7]. Take the list it ends on as the audit scope, though, because it is more concrete than most break-glass documentation: device and laptop access, BitLocker, the password manager's own master credential, then domain registrar, finance, insurance and house control [10]. Every one of those is a single-custodian dependency until someone writes down who inherits it.
Ranked by verification strength, evidence, and original report placement.
A colleague of the author learned that the father of a friend had died; the man had stored his passwords in an encrypted Excel spreadsheet and none of his family knew the password, leaving them locked out of everything.
The deceased was described as tech-savvy, had invested in smart home technology, and used strong and unique passwords everywhere, stored in an encrypted Excel file.
The author used the office2john Python script to extract the hash from the Excel file and ran Hashcat on the firm's most powerful password cracking server.
Initial attempts included brute forcing up to 9 characters, several dictionaries with multiple rules, combinations of words the family suggested, and brute force tasks left running over a weekend; none succeeded.
The family noticed common formats in the passwords he used; in this instance the format was word, number, exclamation, word, which explained why dictionary and brute force attacks failed.
Because Hashcat cannot take that format directly, the author built a custom dictionary from around 80,000 English words with digits and an optional exclamation character appended, then used Hashcat's Combinator attack against the original word list, invoked as: hashcat -m9800 -a1 excel.hash wordsAndNumbers.txt english-88k-upper.txt
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but uncorroborated first-hand account
The account is first-hand and unusually specific for a vendor blog: named tooling, Hashcat mode and attack type, the exact command line, the password format, its length and the failed attack sequence. But it is a single source with a commercial interest, published with no artifacts, hash sample, wordlist, hardware specification or independent benchmark, and the headline throughput and energy figures are self-reported. Nothing in the supplied material can be checked against a second publisher.
One disclosed engagement, no wider uptake data
The only real-world usage evidence is this single recovery engagement plus the firm's disclosure that it runs an offline password auditing service. There is no data in the supplied source on how widely credential estate planning, next-of-kin documentation or password-manager emergency access is actually practised, so adoption is measured low rather than treated as broad.
Capability framing slightly outruns the mechanism
The post's most quotable line - a 13-character mixed-class password cracked in under a minute - reads as a statement about cracking power, while the narrative itself shows weeks of brute force and rule-based dictionary work failing until relatives recalled the format. Derived arithmetic makes the point sharper: the constrained run is around 1.4e11 candidates, versus roughly 5.1e25 for an unconstrained 13-character search. The overstatement is mild and self-corrected in the same text, and the advisory portions are measured rather than promotional, so the gap is small and positive.
Vendor blog demonstrating a service it sells
The piece is published on a penetration testing firm's own security blog by the person who runs its password auditing service, and it doubles as a capability demonstration for offline cracking and a nudge toward the firm's password policy guidance. That does not make the account false - it is a first-hand narrative published with the family's consent and includes an unflattering record of failed attempts - but every figure that flatters the firm's rig is self-reported and unaudited.
Coherent single-source account, thin verification
Confidence is limited by the single-publisher, single-anecdote basis and by unverifiable performance and energy figures, but supported by the account's internal consistency, its technical specificity, and the fact that the derived keyspace arithmetic reconciles with the reported outcome. The advisory content - inventories, emergency access, named technical contact, separating instructions from the systems they unlock - stands on its own regardless of the cracking figures.
security
GivEnergy's administration leaves a backdoor with nobody left to patch it1 distinct publisher
security
Kaspersky's CVE surge has two sources, and only one of them lands in the CVE count1 distinct publisher
build
Excel validation is a gate on one route, and paste walks off with the gate1 distinct publisher
build
The MS-R1 ships KVM but no vhost, so an Android test fleet starts with a kernel build1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026