Data-driven analysis

PDF Password Recovery Feasibility

A universal percentage is not a useful promise. Feasibility depends on the encryption revision, file health, remembered password clues, and the bounded candidate search that can be justified for the owner.

Short answer

R=2 40-bit RC4 is the finite-key exception. R=3/R=4/R=5/R=6 require a password-dependent assessment; strong random passwords are not realistically recoverable.

Clear release process

Free PDF check. Local release price only if recovery works.

Analysis costs $0. If recovery succeeds, the status page shows the result and your local release price before the password or decrypted file is delivered.

Checking local price…

shown before payment

Why recovery feasibility varies

A PDF is not one kind of encrypted file. The PDF specification has gone through four major security revisions since 1993, and each one raised the bar for how much work an attacker has to do to guess a password. The numbers you see on recovery product landing pages average across all of them, which is why they feel dishonest when applied to your specific file.

Two variables dominate the outcome: the encryption revision stored in the file header, and the password composition the original owner picked. The first you can read in seconds. The second you have to estimate. Together they decide whether a bounded technical route is justified.

We do not publish an aggregate percentage without a reproducible cohort, password distribution, attack budget, file-health criteria, and a dated definition of success. The free check reports the feasibility of the individual file instead.

Feasibility by encryption revision

The table below ranks PDF encryption variants from most recoverable to least. These are feasibility categories, not promises of a universal percentage; the result still depends on the password and file details.

EncryptionRevision (R)Typical PDF eraFeasibilityTime window
40-bit RC4R=2Acrobat 3-4 (1996-2000)Finite-key recoveryDepends on file and budget
128-bit RC4R=3Acrobat 5-6 (2001-2005)Password-dependentDepends on clues and budget
AES-128R=4Acrobat 7-9 (2005-2009)Password-dependentDepends on clues and budget
AES-256 (broken)R=5Acrobat 9 onlyWeak passwords onlyDepends on clues and budget
AES-256 (current)R=6Acrobat X+ (2010-now)Weak passwords onlyDepends on clues and budget

R=5 was an early Adobe AES-256 implementation with a known validation flaw that made it significantly faster to attack than R=6. It only appears in files written by Acrobat 9.

40-bit RC4: the finite-key exception

The 40-bit RC4 encryption used in early PDF versions has a key space of 240, roughly one trillion possible keys. That sounds large until you realize a single mid-range GPU can test that entire space in a few hours. No wordlist, no guessing required. The attack targets the key directly, not the password.

Because the attack targets the legacy key space rather than a normal password dictionary, password composition is less important for this specific revision. This is why 40-bit PDF recovery is treated as a finite-key exception, subject to file and implementation checks.

Practical outcome

If the PDF analyzer reports V=1, R=2, 40-bit, the file is a candidate for finite-key analysis. The free check still confirms the file is healthy and the result is valid.

128-bit RC4 and AES-128: the dictionary tier

Once key spaces cross about 256, direct key search stops being realistic. Attacks shift to the password. Curated password corpora and rule-based mangling can cover common human patterns, but coverage depends on the language, context, and search budget. They are useful inputs, not a universal recovery guarantee.

Password patterns change the search space, but a blended percentage is not a reliable assessment for an individual file:

  • Dictionary word or phrase: often a reasonable candidate for a bounded dictionary search.
  • Dictionary word plus digits or symbols: may be testable when the pattern is known.
  • Name, date, or familiar number: useful clues, but the search budget depends on the exact pattern.
  • Random mixed password: usually not realistic without strong additional clues.
  • Long random password: not realistically recoverable through ordinary candidate search.

Do not apply a blended percentage to an individual file. A useful assessment needs the exact revision, file health, remembered password clues, search budget, and a dated definition of success.

AES-256: the hard tier

R=6 AES-256 uses a stronger password-based key derivation function than the early RC4 revisions. Each candidate is substantially more expensive to test, so broad brute force quickly becomes impractical and recovery must rely on justified password clues.

On this tier, a justified search usually relies on owner-provided context, tailored wordlists, or a tightly bounded pattern. Generic brute force is not a responsible plan for a modern AES file.

When AES-256 recovery fails

If the password was generated by a password manager (20+ random characters) or is a truly unrelated long phrase, no current service will recover it in commercially reasonable time. Honest providers will tell you this before taking money.

Why free desktop tools advertise numbers they cannot deliver

Most free Windows apps in the PDF recovery category market heavy success numbers because the math works on their best case scenarios: 40-bit RC4 files and passwords shorter than 5 characters. For anything outside that, they run a small dictionary, stall, and fail.

Common reasons they underperform:

  • Limited compute. Single-device tools have a smaller candidate budget than a managed, hardware-accelerated search.
  • No rule-based mangling. Real cracking combines a wordlist with thousands of transformation rules (capitalize, append 1, swap letters). Free tools run raw dictionaries with no rules.
  • No attack sequencing. Effective recovery runs a graduated sequence: small high-value wordlist first, then PRINCE, then mask, then brute. Free tools pick one mode and stop.

If you have already tried two or three free tools on a modern PDF with no result, the file is almost certainly above their realistic ceiling. That does not automatically mean the password is unrecoverable, only that more compute and a better attack plan are needed.

How we quote honest odds on individual files

Our upload analyzer reads the PDF header locally in your browser and tells you the encryption revision before you commit to anything. Based on the revision and any optional context you provide (a guessed password fragment, an approximate length, or a language), we show a feasibility category specific to that file, not a marketing average.

If the file is outside a realistic candidate space, we say so. If it is a 40-bit RC4 file, we route it to the finite-key recovery flow because the key-space analysis is distinct from ordinary password guessing.

For deeper technical detail on the encryption variants, see PDF encryption types explained. For practical recovery steps once you know what you are dealing with, see the full PDF recovery guide.

Claims to distrust

Be skeptical of any provider advertising "99% success on all PDFs" without specifying the encryption version, "instant recovery" for AES-256, or "guaranteed in 10 minutes." The math does not permit these claims, and the refund policy usually hides behind small print.

Frequently asked questions

Does knowing part of the password help?

Yes, dramatically. Even a guessed length or first character can collapse the search space by orders of magnitude. A mask attack with known structure is often the difference between a 72-hour success and a multi-month failure on AES-256.

Why do identical PDFs recover at different rates?

Because the password, not the file, is the real variable. Two AES-256 PDFs have the same encryption strength but one might use "welcome2024" and the other "x9Kp#mQ2vZ!8rT". The first falls in seconds, the second is out of reach.

Can quantum computers break PDF encryption?

Not for practical customer-side recovery. Quantum attacks on AES-256 would halve the effective key length (Grover's algorithm), but that still leaves 128 effective bits, far beyond any near-future machine. Classical cracking will remain the only realistic path for at least this decade.

Why do some services quote lower prices for weaker PDFs?

Because 40-bit RC4 is essentially a deterministic workload with a fixed compute cost. AES-256 is probabilistic and may require multi-day GPU time. Honest pricing reflects that compute difference rather than pretending all PDFs are equal.

Should I pay for a second attempt if the first fails?

Only if the provider is running meaningfully different attacks. Repeating the same dictionary-plus-rules sequence on the same hardware will not produce a new result. A good provider tells you what they tried and what realistic next steps look like before asking for more budget.

Know your odds before you commit

Upload the file on the home page analyzer. You'll see the encryption version and a conditional feasibility category in seconds, free, with no account required. That individual check is more useful than a blended marketing percentage.