Harvest Now, Decrypt Later: The Hidden Quantum Threat to Your Encrypted Data

Arsalan Rathore
September 2, 2026
Updated on September 2, 2026
Harvest Now, Decrypt Later: The Hidden Quantum Threat to Your Encrypted Data

Somewhere on the internet, someone is copying encrypted files to a very hidden place on the internet. All of the files being copied are currently encrypted and therefore cannot be read by anyone.

This activity does not have the same excitement as you watching someone hacking away at a computer. This activity is done slowly and can be very unsettling.

Somebody – a government agency or a very rich cybercrime gang – will presumably assume that the encryption will fail at some point, and so they’re making a copy of the data in the hope that by the time they can decrypt it, the necessary tools will have been developed.

These types of hacks are often described by security experts in terms of ‘harvest now, decrypt later’. It gives a frightening insight into how online security is actually worked around and once you realize how it is done, it’s difficult to return to the way you were thinking about your online privacy.

What Does “Harvest Now, Decrypt Later” Actually Mean?

This is pretty straightforward to explain today. All encrypted data that is transmitted over the Internet today is encrypted in such a way that it cannot be read by anyone who might intercept it. But that doesn’t mean it will always remain this way.

When quantum computers have reached sufficient power, some part of the math that currently holds the encrypted data will start to break down. Therefore, currently, all traffic is being collected by attackers who are aware of this development and are not waiting for a break-through.

This means that financial records, medical files, government cables and corporate secrets are all currently being collected and stored. None of this data has to make sense right now. It can just be a bunch of seemingly random numbers that right now mean nothing to whoever is holding on to them. But that doesn’t mean it’s going to mean nothing in 10-15 years.

Here’s a simple analogy for the situation. A sealed letter is dropped into a vault with no key yet built to unlock the letter. For now the letter means nothing to the person holding it.

The letter can be taken home, cost-free, and left to wait for the future development of a key. Patience is the weapon of choice here.

Is Quantum Computing Really Close Enough to Worry About?

Ten years ago Quantum Computing was mainly of interest to people in University labs and Science Journalists.

A whole host of very well funded start-ups, including Google and IBM, are building quantum computers to perform calculations that conventional computers are unable to complete.

Progress in quantum computing has not been a straight line and has been slower than some people anticipated when they read about it in the early days of hype. However, it has not stopped.

A few things worth sitting with:

  • Current public key encryption, the kind guarding your bank login, your inbox, and most VPN traffic, leans on math problems like factoring enormous numbers, problems that are basically impossible for regular computers to crack in a useful timeframe.
  • A quantum computer running something called Shor’s algorithm could tear through those same problems far faster, which would leave a lot of today’s encryption looking outdated overnight.
  • Nobody agrees on a timeline. Guesses range anywhere from ten to twenty five years out, and frankly even the experts admit they’re estimating.
  • That uncertainty is exactly why harvesting data now still makes sense for an attacker. Waiting doesn’t cost them anything, and whatever they grab today keeps working whenever the technology finally arrives.

Which Types of Encrypted Data Are Most Valuable to Steal Now?

Storage isn’t free, so attackers don’t bother scooping up everything they come across. They go after data with staying power, the kind that’s still worth something a decade from now.

  • Government and military communications, since secrets in this category tend to stay sensitive for decades, not months.
  • Health records, because a diagnosis or a genetic profile doesn’t lose its sensitivity just because time has passed.
  • Banking and financial data, including account credentials and transaction histories that could still be exploited years down the road.
  • Corporate trade secrets and research data, the kind of intellectual property a competitor would happily pay for even a decade from now.
  • Personal identity information, think Social Security numbers, passport scans, and biometric data, none of which ever really expires.
Which Types of Encrypted Data Are Most Valuable to Steal Now?

Notice what’s absent from that list. Nobody’s building a warehouse to store a meme you sent a friend last Tuesday.

But a decade’s worth of your encrypted browsing habits, shopping history, and saved logins? That’s an entirely different kind of prize.

What Do the Numbers Say About the Quantum Threat?

Reading this as a hypothetical, someday sort of problem gets a lot harder once the industry surveys come out. A few recent figures put real weight behind the concern.

  • DigiCert’s 2026 Quantum Readiness Outlook found that 85 percent of IT and security leaders believe quantum computing will break today’s encryption standards within a decade, yet only 7 percent have deployed quantum-safe certificates at scale.
  • The same DigiCert survey found that 84 percent of organizations believe at least some of their encrypted data is already exposed to harvest now, decrypt later attacks.
  • The Global Risk Institute’s Quantum Threat Timeline Report 2025 puts expert odds of a cryptographically relevant quantum computer emerging within ten years at 28 to 49 percent, rising to 51 to 70 percent within fifteen years.
  • A 2025 ISACA survey covered by CSO Online found that only 5 percent of cyber professionals treat the quantum threat as a high priority, even though two thirds are concerned about quantum’s future ability to break encryption.
  • IBM’s Institute for Business Value scored the average organization at just 25 out of 100 on its Quantum-Safe Readiness Index in 2025, up only slightly from 21 in 2023.
  • Research from Google Quantum AI, reported by CSO Online cut the estimated qubits needed to break RSA-2048 encryption from roughly 20 million down to about 1 million, a twentyfold drop from earlier estimates.
  • NIST’s official announcement confirms the agency finalized its first three post-quantum cryptography standards in August 2024, giving the industry an actual technical blueprint to migrate toward instead of just a warning.

None of these numbers predict an exact date. But taken together, they explain why security teams keep treating harvest now, decrypt later as a today problem instead of a someday one.

Classical Encryption vs Post-Quantum Encryption: How Do They Compare?

Sometimes a table just does the explaining better than another few paragraphs could.

AspectClassical Encryption (RSA, ECC)Quantum-Resistant Encryption (Post-Quantum Cryptography)
Security basisRelies on factoring large numbers or elliptic curve mathRelies on lattice-based, hash-based, or code-based problems
Vulnerable to quantum attacksYes, breakable by Shor’s algorithm on a mature quantum computerDesigned specifically to resist quantum attacks
Current adoptionStandard across most websites, VPNs, and banking systems todayStill rolling out, with NIST standards published in 2024
Processing overheadLightweight, fast, minimal impact on speedGenerally heavier, though improving with newer algorithms
Long-term data safetyAt risk for anything intercepted and stored todayBuilt with long-term confidentiality in mind

None of this is meant to sound alarming. If anything, it shows the opposite.

The industry already saw this coming, and the shift toward quantum resistant standards is underway. It’s just not finished yet, and that gap is where the risk currently lives.

How Does the Quantum Threat Affect Everyday Internet Users?

I thought this post would relate to spies and defense contractors, but it really does not.

There are lots of examples of people sending data over the internet using encryption (the same type used by spies and defense contractors who are worried about quantum computing). For example, people who log onto their online bank accounts, complete online medical intake forms, or shop on online marketplaces have, at some stage, sent data over the internet using encryption.

Just think about logging onto email, paying bills on-line, or checking into for a medical procedure on-line – all of this data is being transferred across the Internet using encryption.

Go to a coffee shop and check your email or pay a bill while connected to the public Wi-Fi there. Watch your traffic be easily intercepted in a matter of seconds before the issue of quantum computing even arises.

Running a VPN will encrypt your connection to the point of origin, thus reducing the amount of data that can be intercepted by someone harvesting data now and stored to be cracked later.

This won’t help against quantum computing in 15 years or so, but it does help against what gets harvested today. Less data being intercepted today means less data is stored to be cracked open later.

How Is the Cybersecurity Industry Preparing for Quantum Attacks?

But there is good news for now, since this threat has not yet surprised the security community, and thus something is being done about it.

The U.S. National Institute of Standards and Technology (NIST) has completed the first set of post-quantum cryptography standards and finalized them in 2024 after years of testing of the various candidate algorithms for resistance to quantum computers.

Large technology companies, including browsers, instant messaging services and VPN services, are already starting to deploy post-quantum cryptography.

AstrillVPN is monitoring this development closely. The point of using a VPN is to have encryption that will hold up twenty years from now.

It is not possible to implement quantum-resistant algorithms overnight. They need to be tested, made compatible with existing infrastructure, and then gradually implemented.

But there is work being done to put in place quantum resistant algorithms to prevent having to implement them once quantum computers have become powerful enough to break current public key cryptography. Providers are already making the change to quantum resistant algorithms for current public key cryptography.

How Can You Protect Your Data From Harvest Now, Decrypt Later Attacks?

None of this calls for panic or ripping up your entire digital routine. A handful of practical habits go a surprisingly long way.

  • Use a VPN with strong, current encryption protocols any time you’re connecting through public or unfamiliar networks.
  • Steer clear of sending sensitive documents, medical records or financial statements especially, through unsecured email.
  • Keep your software and apps updated, since patches often quietly bring in stronger cryptographic support without any fanfare.
  • Keep an eye on which platforms and providers are actually moving toward post quantum standards, rather than just talking about it.
  • Share less personal data online in general. Information that was never collected in the first place can’t end up in anyone’s harvest pile.

Frequently Asked Questions

Is my data at risk today if quantum computers don’t exist yet?

No. Not yet. That means that right now no one can yet read out the intercepted data of users. It will become possible as soon as a sufficient powerful quantum computer has been built.

How soon could quantum computers actually break current encryption?

It is not possible to give a date for when a general purpose quantum computer will be available. Instead we can give rough estimates of when it might happen, and most people think this will be in the range of 10 to 25 years, depending on progress with hardware as well as with error correction.
Some even predict that quantum computing will arrive much sooner than currently predicted, while others predict it will even take longer.

Does this mean VPNs are useless against future quantum attacks?

Not even close. A VPN’s core job, encrypting your connection and shrinking what’s exposed to interception, still matters today regardless of where quantum computing ends up.
Reputable VPN providers are also actively working toward adopting post quantum encryption standards as the technology matures, so this protection isn’t sitting still either.

What kind of data is most at risk from this threat?

Data with real staying power is the target here: government records, health information, financial details, biometric identifiers, and trade secrets.
Basically, anything that stays sensitive for years or decades is worth harvesting now, unlike data that loses its relevance within weeks.

Do current data breach laws even cover this type of attack?

I think most breach notification laws were intended to be used in the immediate wake of a data theft and subsequent data breach. They were not really intended to be used in a scenario where data is stolen and then just sits idle for years until the information is actually used for malicious purposes.
Determining where harvest now, decrypt later belongs in current framework of laws, and crafting new laws to address emerging technology, will take time from the regulatory and legislative communities.

Secure instantly - Try AstrillVPN

Secure your privacy instantly. Try AstrillVPN with zero risk.

Get AstrillVPN

Was this article helpful?
Thanks for your feedback!

About The Author

Arsalan Rathore is a tech geek who loves to pen down his thoughts and views on VPN, cybersecurity technology innovation, entertainment, and social issues. He likes sharing his thoughts about the emerging tech trends in the market and also loves discussing online privacy issues.

No comments were posted yet

Leave a Reply

Your email address will not be published.