← All Terms

Harvest Now, Decrypt Later

An attack in which an adversary records encrypted traffic today and stores it until a quantum computer can recover the keys and read it.

Governance & Risk

Harvest now, decrypt later describes an adversary who copies encrypted data in transit today without being able to read it, and keeps it until a cryptographically relevant quantum computer can break the key exchange that protected it. Storage is cheap, so a patient attacker loses nothing by waiting.

It is why the quantum threat to confidentiality has already started even though no such computer exists. Michele Mosca’s rule of thumb sets the test: if the years your data must stay secret plus the years your migration will take exceed the years until a quantum computer arrives, the data is already exposed. Health records, state secrets, trade secrets, proprietary training data and model weights all have secrecy lives measured in years.

The defence is to move key exchange to post-quantum or hybrid algorithms first, ahead of signatures, for any link that carries long-lived data. Signatures face a different threat, forgery, which only begins once the machine exists.