PLAIN QUANTUM
← All articles
Security

"Harvest now, decrypt later," explained

On this page
  1. The strategy in one paragraph
  2. Why quantum makes this possible
  3. Who would do this?
  4. Which data is at risk?
  5. Why payments data is a textbook target
  6. A story in two dates
  7. Isn't storing everything impractical?
  8. What harvesting doesn't threaten
  9. The fix is already rolling out
  10. What you can do
  11. Sources and further reading

Quantum computers that can break today's encryption don't exist yet. So why are security agencies warning that some data is already at risk? The answer is a strategy with a blunt name: harvest now, decrypt later. It's the main reason quantum security is a today problem and not a someday problem.

The strategy in one paragraph

An attacker can't read encrypted data today. But they can copy it. Encrypted traffic flows across the internet, through undersea cables and data centres, and anyone in the right position can record it. Storage is cheap, so a determined attacker can keep enormous amounts of it for years. Then, when a sufficiently powerful quantum computer becomes available, they break the encryption on the old recordings and read everything inside.

The attack happens in two stages, possibly a decade apart. The first stage is happening now.

Why quantum makes this possible

Recall the two kinds of lock from Why your bank is already preparing. When your phone opens a secure connection, it uses public-key cryptography to agree a fresh secret key with the server, then uses that key with symmetric encryption to protect the data.

An attacker who recorded the whole conversation has the public-key part of that exchange on file. Today it's useless to them. But Shor's algorithm, run on a large quantum computer, could work backwards from that recorded exchange to recover the secret key. With the key, the rest of the recording opens up.

Who would do this?

Not ordinary criminals. Harvesting traffic at scale and storing it for a decade takes patience and resources, and the payoff is years away. The realistic actors are well-funded intelligence agencies and similar organisations, interested in information that will still be valuable later: government and military communications, diplomatic cables, corporate secrets, research and personal data about people of interest.

Security agencies take this seriously. In 2023, US agencies including CISA, the NSA and NIST published joint guidance urging organisations to prepare for post-quantum cryptography, pointing out that adversaries could be collecting encrypted data now to decrypt in the future.

Which data is at risk?

The question that matters is how long the data needs to stay secret. Some examples:

  • Short-lived: a one-time login code, today's weather lookup, a message saying you're running late. Nobody cares about these in ten years.
  • Medium-lived: business plans, merger negotiations, most financial transactions. Sensitive for a few years.
  • Long-lived: health records, legal and tax records, mortgage files, state secrets, trade secrets and biometric data. You can change a password, but you can't change your fingerprints or your medical history.

If the data's useful life is longer than the time until a capable quantum computer, it's exposed to harvesting today. That's the heart of Mosca's inequality, which the bank article illustrates with a chart.

Notice what this rule doesn't need: a date. Nobody knows when a capable quantum computer will arrive, and anyone quoting a confident year is guessing. You only need to believe your data must stay secret for longer than the most optimistic estimate. For health, legal and financial records, that's an easy call.

The data was secure when it was sent. It becomes readable in hindsight. The breach happened the moment it was recorded.

Why payments data is a textbook target

Harvesting pays off when data is valuable, long-lived and easy to capture in transit. Payment data ticks every box. Transaction records and account details carry legal retention and confidentiality obligations measured in years or decades. They reveal who pays whom, which is valuable intelligence in itself. And they flow constantly over networks between banks, processors and payment systems. A payment sent in 2026 still reveals account relationships and personal details years later.

That's why, in banking, the encrypted connections between systems are treated as the front line. Every recorded handshake that used today's key exchange is a potential future decryption.

A story in two dates

To make it concrete, here's an illustrative scenario. The details are invented, but the mechanics are real.

2026. A hospital sends patient records to a specialist clinic over an encrypted connection using today's standard key exchange. Somewhere along the route, an intelligence agency is recording traffic to and from that region. The recording is unreadable, so it's filed away with millions of others, tagged by sender and date.

2038. The same agency now has access to a quantum computer capable of running Shor's algorithm at scale. It pulls the old recordings for a list of people of interest, recovers the session keys and reads the files. The patients' diagnoses are still accurate, still sensitive and still usable for blackmail or influence, twelve years later.

Nothing in 2026 looked like an attack. No alarms went off, nothing was stolen in a way anyone could detect, and the encryption worked exactly as designed. That's what makes the threat hard to argue about inside organisations: there's no incident to point to, only arithmetic.

Isn't storing everything impractical?

Storing all internet traffic forever would be. But attackers don't need everything. They can target specific links, organisations or people, and keep only what looks valuable. Storage costs keep falling, and recordings compress well. For an agency with a clear list of targets, keeping years of selected traffic is well within reach.

The selectiveness also tells you who should worry most: governments, defence, critical infrastructure, large financial institutions, healthcare, and anyone holding secrets with a long shelf life.

What harvesting doesn't threaten

Harvest now, decrypt later is a threat to confidentiality: secrets being read. It's a smaller direct threat to signatures, the cryptography that proves who sent something.

A recorded signature from 2026 isn't much use to an attacker in 2036; they'd want to forge new ones. That threat starts only once a quantum computer actually exists. But it still needs early planning, because the systems that check signatures, such as payment cards, devices' software update systems and the certificates that underpin trust between organisations, can take many years to replace.

So there are really two clocks: a confidentiality clock that is already running because of harvesting, and a signature clock that starts on Q-day but needs a long run-up.

The fix is already rolling out

The defence is to switch key agreement to post-quantum algorithms like ML-KEM, so that a recording made today can't be unlocked later. Most deployments use a hybrid approach: they combine a traditional algorithm with a post-quantum one, so the connection stays secure as long as either of them holds.

A lot of this has already happened without anyone noticing:

  • Signal added post-quantum protection to its messaging in 2023, and Apple added it to iMessage in 2024.
  • Google Chrome and other major browsers, along with large networks such as Cloudflare, turned on hybrid post-quantum key agreement by default during 2024.

That means a meaningful share of everyday web traffic is already protected against harvesting. The harder work is in older systems: internal corporate networks, connections between businesses, industrial equipment and financial infrastructure, where upgrades take years.

What you can do

As an individual: keep your phone, browser and messaging apps updated. That's genuinely the main step, because the protections arrive through updates. Use reputable apps that publish their security approach.

As an organisation: identify which of your data must stay confidential for many years, find which systems carry it, and put those first in line for post-quantum key agreement. Ask your vendors when their products support it.

Three things to remember
  • Encrypted data recorded today could be decrypted once a large quantum computer exists.
  • The risk depends on how long the data must stay secret. Long-lived secrets are exposed now.
  • Post-quantum key agreement stops harvesting, and it's already switched on in many browsers and apps.

Sources and further reading

Tags show what kind of source each one is. A standard or government guidance is an official document; a peer-reviewed paper has been checked by other experts; a preprint has not been peer-reviewed yet; an experiment reports a real-world demonstration; a company announcement is the company's own account. Dates and figures were checked against these sources on 11 October 2026. Spotted an error? Email hello@plainquantum.com and it will be corrected, with a note.

  1. Government guidanceQuantum-Readiness: Migration to Post-Quantum CryptographyCISA, NSA and NIST, 2023
  2. Peer-reviewed paperCybersecurity in an era with quantum computers: will we be ready?Michele Mosca, IEEE Security & Privacy, 2018
  3. Government guidanceRoadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)Canadian Centre for Cyber Security, 2025
  4. Company announcementQuantum resistance and the Signal ProtocolSignal, 2023
  5. Company announcementiMessage with PQ3: the new state of the art in quantum-secure messaging at scaleApple Security Research, 2024
  6. Company announcementProtecting Chrome traffic with hybrid Kyber KEMChromium blog, 2023
  7. Company announcementThe state of the post-quantum InternetCloudflare, 2024