How harvest now, decrypt later works
- Collect. Copy encrypted traffic where it passes through a network, or take encrypted files and backups in a breach. Storage is cheap, so there is little reason to be picky.
- Wait. Keep the copies until a cryptographically relevant quantum computer exists. Estimates for that moment, called Q-Day, mostly land in the 2030s.
- Decrypt. Use Shor’s algorithm to solve the RSA or elliptic-curve key exchange recorded at the start of each session. That reveals the session key, and the session key opens everything sent under it.
The attacker never has to break AES. They break the handshake that delivered the AES key. That is why the fix is in the key exchange, not the cipher.
Security planners use a simple test known as Mosca’s inequality: if the number of years your data must stay secret plus the years it takes you to migrate is larger than the years until Q-Day, you are already exposed.1
| What was sent | How long it stays sensitive |
|---|---|
| Medical and health details | A lifetime |
| Legal matters and contracts | Decades |
| Identity documents and financial records | As long as the numbers stay valid |
| Business plans and source code | Years |
| A one-time login code | Minutes |
Why it matters now
The collection step needs no quantum computer, so it can happen today. In a joint 2023 factsheet, CISA, the NSA and NIST warned that attackers could be targeting data now that needs protection in the future, in what they call a “catch now, break later” operation.2 Google’s security team wrote in March 2026 that encryption already faces immediate risk from store-now-decrypt-later attacks, and moved its own post-quantum migration deadline to 2029.3
There is one detail most explainers miss: you can’t fix a copy after it’s taken. Upgrading your encryption next year protects what you send next year. What was recorded under the old key exchange stays exactly as breakable as it was. The only defense is to use a post-quantum key exchange, such as ML-KEM, before the data is sent.
Where you’ll see it
- Government guidance. The UK’s NCSC asks organizations to finish moving to post-quantum cryptography by 2035, with milestones in 2028 and 2031.4 NIST proposes retiring RSA and elliptic-curve key exchange after 2030 and 2035.5
- Product launches. Apple introduced iMessage PQ3 in 2024 specifically to counter harvest now, decrypt later.6 Browsers and CDNs switched on hybrid ML-KEM for the same reason, and Cloudflare says over 65% of human traffic it serves is now post-quantum encrypted.7
How Secria handles it
Secria Mail seals every message in your mailbox with ML-KEM-1024 hybrid encryption, on every plan, so there is nothing left for a future quantum computer to unlock. Secria VPN protects every session with an ML-KEM-1024 preshared key, so captured traffic stays sealed. Read why post-quantum email matters, or see post-quantum email and the post-quantum VPN.
Related terms
Sources
- Global Risk Institute and evolutionQ, Quantum Threat Timeline Report 2025 (March 2026).
- CISA, NSA and NIST, Quantum-readiness: migration to post-quantum cryptography (August 2023).
- Google, Quantum frontiers may be closer than they appear (March 2026).
- UK NCSC, Timelines for migration to post-quantum cryptography (March 2025).
- NIST, IR 8547 (initial public draft): Transition to Post-Quantum Cryptography Standards (November 2024).
- Apple Security Research, iMessage with PQ3 (February 2024).
- Cloudflare, Cloudflare targets 2029 for full post-quantum security (April 2026).
Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.