Glossary

What is harvest now, decrypt later?

Harvest now, decrypt later is an attack where someone records encrypted data today and stores it until a quantum computer can break the encryption. It works because most traffic still relies on key exchanges a large quantum computer could crack, so anything that must stay secret for years is already exposed once it’s copied.

Also called: HNDL, store now, decrypt later, catch now, break later

Updated September 2026. Sources are numbered and listed at the end.

How harvest now, decrypt later works

  1. Collect. Copy encrypted traffic where it passes through a network, or take encrypted files and backups in a breach. Storage is cheap, so there is little reason to be picky.
  2. Wait. Keep the copies until a cryptographically relevant quantum computer exists. Estimates for that moment, called Q-Day, mostly land in the 2030s.
  3. Decrypt. Use Shor’s algorithm to solve the RSA or elliptic-curve key exchange recorded at the start of each session. That reveals the session key, and the session key opens everything sent under it.

The attacker never has to break AES. They break the handshake that delivered the AES key. That is why the fix is in the key exchange, not the cipher.

Security planners use a simple test known as Mosca’s inequality: if the number of years your data must stay secret plus the years it takes you to migrate is larger than the years until Q-Day, you are already exposed.1

Illustrative examples. How long something stays sensitive depends on the person and the data.
What was sentHow long it stays sensitive
Medical and health detailsA lifetime
Legal matters and contractsDecades
Identity documents and financial recordsAs long as the numbers stay valid
Business plans and source codeYears
A one-time login codeMinutes

Why it matters now

The collection step needs no quantum computer, so it can happen today. In a joint 2023 factsheet, CISA, the NSA and NIST warned that attackers could be targeting data now that needs protection in the future, in what they call a “catch now, break later” operation.2 Google’s security team wrote in March 2026 that encryption already faces immediate risk from store-now-decrypt-later attacks, and moved its own post-quantum migration deadline to 2029.3

There is one detail most explainers miss: you can’t fix a copy after it’s taken. Upgrading your encryption next year protects what you send next year. What was recorded under the old key exchange stays exactly as breakable as it was. The only defense is to use a post-quantum key exchange, such as ML-KEM, before the data is sent.

Where you’ll see it

  • Government guidance. The UK’s NCSC asks organizations to finish moving to post-quantum cryptography by 2035, with milestones in 2028 and 2031.4 NIST proposes retiring RSA and elliptic-curve key exchange after 2030 and 2035.5
  • Product launches. Apple introduced iMessage PQ3 in 2024 specifically to counter harvest now, decrypt later.6 Browsers and CDNs switched on hybrid ML-KEM for the same reason, and Cloudflare says over 65% of human traffic it serves is now post-quantum encrypted.7

How Secria handles it

Secria Mail seals every message in your mailbox with ML-KEM-1024 hybrid encryption, on every plan, so there is nothing left for a future quantum computer to unlock. Secria VPN protects every session with an ML-KEM-1024 preshared key, so captured traffic stays sealed. Read why post-quantum email matters, or see post-quantum email and the post-quantum VPN.

Sources

  1. Global Risk Institute and evolutionQ, Quantum Threat Timeline Report 2025 (March 2026).
  2. CISA, NSA and NIST, Quantum-readiness: migration to post-quantum cryptography (August 2023).
  3. Google, Quantum frontiers may be closer than they appear (March 2026).
  4. UK NCSC, Timelines for migration to post-quantum cryptography (March 2025).
  5. NIST, IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards (November 2024).
  6. Apple Security Research, iMessage with PQ3 (February 2024).
  7. Cloudflare, Cloudflare targets 2029 for full post-quantum security (April 2026).

Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about harvest now, decrypt later

Is harvest now, decrypt later happening today?+

US security agencies treat it as a present threat, because collecting encrypted data needs no quantum computer. Public proof of specific campaigns is rare, since the whole point is to stay quiet until decryption becomes possible.

What data is at risk?+

Anything sent or stored under RSA or elliptic-curve key exchange that will still matter when large quantum computers arrive: health and legal records, identity documents, business plans and private email.

Does forward secrecy protect against harvest now, decrypt later?+

No. Forward secrecy protects past sessions if a long-term key is stolen later. A quantum computer attacks the recorded key exchange itself, so it can recover each session key directly.

How do I protect against it?+

Use services that already run a post-quantum key exchange such as ML-KEM, ideally combined with a classical one. For email and VPN traffic, pick a provider that turns it on by default, since protection only covers what is sent after it is switched on.

Email that’s ready for what comes next. Post-quantum encryption on every plan, free included.