Sheet protection in Excel is not the same as encrypting the whole file. If you forgot the password on Protect Sheet in a workbook you own, a known VBA technique - PasswordBreaker - can find a collision in the weak 16-bit hash and unlock the sheet. The method does not help against open passwords, workbook encryption, or files you have no right to change.
Use this only on your own workbooks, or where the owner asked you for help. Bypassing protection on someone else’s documents without permission is illegal.
Sheet protection versus file encryption
Excel has several layers of “password”, and they get mixed up often.
Sheet protection limits editing of cells, formulas, rows, and columns on one sheet. Microsoft describes the feature in Protect a worksheet. The password here is meant as a brake against accidental edits, not as strong cryptography. Historically the check value is stored as a short hash. That is why a brute-force search for hash collisions is practical.
Workbook structure can also be protected (lock sheet tabs, prevent inserting or deleting sheets). That is still not file encryption.
File encryption / open password encrypts the content so the file cannot be read without the correct password. Microsoft documents this separately in Protect an Excel file. PasswordBreaker and similar macros never reach this layer. If you forgot the open password, you need a backup without encryption, your password archive, or official recovery for files you own - not the sheet macro in this article.
In short: sheet protection = edit lock with a weak hash. File encryption = real encryption. This guide covers only the first.
Why PasswordBreaker works: 16-bit hash collision
Classic sheet protection in Excel does not check the password character by character against a strong key table. It compares a 16-bit hash of what you type with the hash stored when the sheet was protected.
A 16-bit value has only 65,536 possible outcomes. Many different password strings hash to the same number. When ActiveSheet.Unprotect gets a string that hits the same hash, it is accepted - even if it is not the original password.
PasswordBreaker uses this in a practical way: the macro systematically tries short character combinations until ProtectContents becomes False. It then reports one working string. That is a hash collision, not “cracking” modern AES encryption.
This is a known, old property of sheet protection. Microsoft’s VBA unlock API is Worksheet.Unprotect (documentation). When you know or find an accepted password (or collision), it is the same API Excel itself uses.
Prerequisites before you start
- You own the file, or have written or spoken permission from the owner.
- The file opens without an open password (otherwise the problem is file encryption, not sheet protection).
- Macros are allowed for this workbook.
- You can reach the VBA editor (
Alt+F11on Windows; on Mac: Tools > Macro > Visual Basic Editor, depending on Excel version).
Copy the file first. The macro writes the found string to cell A1 on the first sheet. On a copy that does not harm production data.
How to run PasswordBreaker
- Open the Excel file and activate the protected sheet.
- Press Alt+F11 to open the VBA editor.
- Choose Insert > Module.
- Paste the code below into the module window.
- Place the cursor inside
PasswordBreakerand press F5 (or Run > Run Sub/UserForm). - Wait until the message box shows a usable password string. The sheet should now be unlocked.

Sub PasswordBreaker()
Dim i As Integer, j As Integer, k As Integer
Dim l As Integer, m As Integer, n As Integer
Dim i1 As Integer, i2 As Integer, i3 As Integer
Dim i4 As Integer, i5 As Integer, i6 As Integer
On Error Resume Next
For i = 65 To 66: For j = 65 To 66: For k = 65 To 66
For l = 65 To 66: For m = 65 To 66: For i1 = 65 To 66
For i2 = 65 To 66: For i3 = 65 To 66: For i4 = 65 To 66
For i5 = 65 To 66: For i6 = 65 To 66: For n = 32 To 126
ActiveSheet.Unprotect Chr(i) & Chr(j) & Chr(k) & _
Chr(l) & Chr(m) & Chr(i1) & Chr(i2) & Chr(i3) & _
Chr(i4) & Chr(i5) & Chr(i6) & Chr(n)
If ActiveSheet.ProtectContents = False Then
MsgBox "One usable password is " & Chr(i) & Chr(j) & _
Chr(k) & Chr(l) & Chr(m) & Chr(i1) & Chr(i2) & _
Chr(i3) & Chr(i4) & Chr(i5) & Chr(i6) & Chr(n)
ActiveWorkbook.Sheets(1).Select
Range("a1").FormulaR1C1 = Chr(i) & Chr(j) & _
Chr(k) & Chr(l) & Chr(m) & Chr(i1) & Chr(i2) & _
Chr(i3) & Chr(i4) & Chr(i5) & Chr(i6) & Chr(n)
Exit Sub
End If
Next: Next: Next: Next: Next: Next
End SubWhat the code does, line by line
- Nested
Forloops build candidate strings from character codes (mostlyA/Bin the early positions, then a wider set in the last position). - Each candidate is sent to
ActiveSheet.Unprotect. - When
ProtectContentsisFalse, the hash was hit. The macro shows the string and exits. On Error Resume Nextskips errors when an attempt misses; that is expected during the search.
The run can take from a few seconds to a few minutes, depending on the machine and Excel version. It does not need to “find” the original password - only one collision.
After unlock: remove protection properly
When the sheet is open, go to Review > Unprotect Sheet if the button is still active, or protect the sheet again with a password you remember and store in a password manager. Do not rely on the collision string being easy to recall.
Unhiding a hidden sheet
Unlocking protection is not the same as unhiding a sheet. If the sheet is only hidden (not VeryHidden):
- On the Home tab, in the Cells group, click Format.
- Under Visibility, choose Hide & Unhide, then Unhide Sheet.
- In the Unhide dialog, double-click the sheet name you want to show.
You can unhide only one sheet at a time.
If the sheet was hidden with VBA via xlSheetVeryHidden, Unhide will not work. Then you must change the property in the VBA editor (Properties for the sheet), or the workbook owner must do it. Do not assume PasswordBreaker fixes VeryHidden - that is a different mechanism.
Notes for Microsoft 365 and newer Excel
Microsoft 365 and current Excel builds (Windows and Mac) still support sheet protection and VBA Unprotect for classic workbooks. Practical limits:
- Macro security. Files downloaded from the web or email may open in Protected View. You must enable editing and allow macros for your own copy before VBA runs.
- Trust Center. Organisations can block all macros by policy. Then IT must allow macros, or you run recovery on a machine where you have rights.
- Mac. VBA exists in Excel for Mac, but shortcuts and menu names differ from Windows. The
Unprotectlogic itself is the same. - Excel on the web / mobile. The web client and mobile apps do not give full VBA. Use desktop Excel.
- Stronger locks. Newer workflows such as IRM, sensitivity labels, or real file encryption sit outside this macro. Do not expect a hash collision to open them.
If Unprotect never succeeds and the file already asked for a password when you opened it, you have file encryption - stop here and use the correct recovery path for your own encrypted files.
Common mistakes and limits
- Wrong layer. You run the macro on an encrypted file. It will not help.
- Wrong sheet active. The macro runs against
ActiveSheet. Activate the correct tab first. - VBA project locked. A separate password on the VBA project is not sheet protection. PasswordBreaker does not solve that.
- Shared / read-only. Save a local copy you can change.
- Expecting the original password. The message box shows a collision, not proof of what someone typed years ago.
Ethics and ownership
The technique is publicly known because the sheet-protection hash is too weak to protect secrets. It stops accidental edits; it does not hide data from outsiders.
Use it to recover your own sheets - old budget workbooks, stock lists, or templates where the password was lost. Do not use it against other people’s files, stolen workbooks, or documents you only have temporary access to. If someone asks you to “unlock” a file they do not own, refuse.
For secrets that must stay secret: use file encryption, SharePoint/OneDrive access control, or a dedicated secret store - not sheet protection alone.
Practical example: forgotten password on your own budget sheet
You inherit a .xlsx from a former colleague. The file opens without a prompt. Formulas are visible, but cells are locked, and Unprotect Sheet asks for a password nobody remembers. That is sheet protection.
You copy the file to budget-copy.xlsx, allow macros, paste PasswordBreaker, run it on the relevant sheet, note the collision string, remove protection, and save without a password (or with a new one in your password manager). Then delete the macro module if you no longer need it.
If Excel had asked for a password already when you double-clicked the file, you would have stopped. Then the content is encrypted, and this article does not apply.
When you should ask the owner instead
Some workbooks sit inside an accounting system, a contract template, or a shared SharePoint library. Even if you can unlock a sheet technically, internal rules may require IT or the owner to do it. Document what you did (date, filename, that it was sheet protection).
If you are unsure about ownership, do not run the macro. Ask for an unprotected export, or ask the owner to remove protection themselves.
Short summary
- Confirm the problem is sheet protection, not file encryption.
- Work only on your own (or authorised) files; take a copy.
- Run PasswordBreaker via VBA to find a 16-bit hash collision.
- Save a new memorable password - or remove protection if you do not need it.
- For encrypted files: different process, different tools, same ownership requirement.
Microsoft’s own pages on sheet protection, Worksheet.Unprotect, and file protection are the reference points when you need to tell the layers apart.







