No need to brute force - if users re-used their master password, it will potentially cross-reference with the correct email and password combo from any number of previous data breaches and pwnage across the net.
Either rent some machines from an ex-crypto miner, since AES can be decyphered on GPUs or get some old extremely cheap boxes from the hetzner auction.