Cybersecurity has historically operated on a fundamental assumption: breach detection and incident response are oriented around the moment of compromise. When an adversary breaches a perimeter, security operations centres rely on integrity check failures, anomalous lateral movement, or unauthorised access logs to trigger an alert. The “Harvest Now, Decrypt Later” (HNDL) strategy systematically dismantles this paradigm.
HNDL is not a localised breach; it is a passive, temporal intelligence operation. When an adversary intercepts encrypted traffic whether it is a transmission between an AI training cluster and a cloud backend, or diplomatic communications routed internationally, the data is collected in a currently unreadable state. Because the payload remains encrypted during transit, no security anomaly is flagged. The breach happens in reverse: the data is exfiltrated today, but the actual exploitation is delayed for a future “Q-Day” when a Cryptographically Relevant Quantum Computer (CRQC) comes online (Palo Alto Networks, 2026).
The intelligence community is facing a unique crisis. The encryption securing the internet today is mathematically sound against classical computers, but the data being stolen in 2026 does not need a quantum computer to be useful today, it only requires the adversary to have patience and storage capacity (Quantum Zeitgeist, 2026).
1. The Silent Archive: Anatomy of Passive Interception
To amass these silent archives, state-sponsored adversaries and advanced persistent threats (APTs) rely primarily on two avenues of interception: manipulating the logical routing of the internet and exploiting its physical infrastructure.
At the network layer, the internet relies on the Border Gateway Protocol (BGP) to route traffic between Autonomous Systems (AS). Designed in the internet’s infancy, BGP operates on implicit trust and lacks native cryptographic verification for routing announcements. Adversaries exploit this structural flaw through BGP Hijacking. By falsely announcing ownership of specific IP prefixes, often utilising longest-prefix-match techniques attackers can effectively deceive global routers into sending traffic through adversary-controlled networks (Keyfactor, 2026).
For the victim organisation, this diversion is practically invisible. The encrypted data still reaches its intended destination, but only after passing through an intercepted node where terabytes of ciphertext are mirrored and archived. Because BGP hijacking occurs at the global routing layer, corporate firewalls and standard event management systems are completely blind to the interception.

While logical attacks target routing, physical attacks target the backbone of global communication. Approximately 99% of intercontinental internet traffic travels across a network of over 500 undersea fibre-optic cables. This physical layer presents a massive vulnerability, particularly in international waters where legal jurisdiction remains murky. The practice of tapping subsea cables is an established intelligence tactic, but the modern scale is unprecedented. Submarines and specialised deep-sea submersibles are utilised to install optical splitters directly onto the fibre lines. By siphoning photons as they travel, adversaries capture raw, encrypted data streams in bulk.
Defending against this physical interception requires interventions at the hardware level. Optical Layer Encryption (or photonic shielding) is increasingly being deployed to counter this. Unlike algorithmic encryption, which protects the digital payload, photonic shielding alters the physical optical waveform itself often by burying the signal in spectral noise preventing an attacker from capturing a valid physical signal in the first place (Keyfactor, 2026).
2. The Lifespan of Secrets: Categorising the Harvest
The economics of a “Harvest Now, Decrypt Later” operation are fundamentally asymmetrical. For an attacker, the cost of intercepting and storing encrypted data enabled by plummeting cloud storage prices is negligible. However, not all data justifies the effort of long-term warehousing. The operational logic of HNDL hinges entirely on the concept of data decay and the resulting “shelf life” of the stolen information. If the data loses its strategic or financial value before quantum decryption becomes viable, the harvest is worthless.
Most commercial data decays rapidly. A payload of encrypted credit card numbers, for instance, has a maximum functional shelf life of three to five years before the cards expire (ISC2, 2026). If Q-Day is a decade away, harvesting this data yields no actionable intelligence. In contrast, high-value targets are defined by their long-tail strategic relevance. Adversaries prioritise data that will remain potent, actionable, or legally damaging well into the 2030s. This includes:
- Aerospace and Defence R&D: Development cycles for next-generation airframes, weapons systems, and advanced materials span decades. Proprietary engineering blueprints and materials science data stolen today will still provide a critical competitive or military advantage in fifteen years.
- Geopolitical Intelligence and Source Identities: Diplomatic cables, long-term national security strategies, and the identities of undercover intelligence assets require absolute confidentiality for up to half a century. The delayed exposure of this information could unravel decades of geopolitical manoeuvring.
- Genome and Biometric Data: Unlike passwords or financial tokens, biological data is immutable. Large-scale theft of genomic sequencing provides state actors with permanent leverage and intelligence that never expires.
Paradoxically, the same regulations designed to enforce transparency and protect consumers are creating vast repositories of HNDL targets. The financial sector is often mandated by federal authorities to retain transactional data for seven to ten years. Similarly, the healthcare sector is bound by privacy laws to maintain patient records for at least six years, with some occupational health records requiring up to 30 years of retention. These localised regulatory mandates inadvertently build highly concentrated, long-term archives. Large enterprises beginning their migration to post-quantum cryptography in 2026 face a meaningful risk window where quantum-capable decryption may become feasible before their legacy data naturally decays (Cloud Security Alliance, 2026).
3. The Cryptographic Fault Line: Shor’s Algorithm and Legacy Infrastructure
The temporal urgency of HNDL is driven by the accelerating timeline of quantum computing development and the mathematical reality of Shor’s Algorithm. Developed in 1994, Shor’s Algorithm proved that a sufficiently powerful quantum computer could find the prime factors of an integer in polynomial time. While the best classical algorithms scale exponentially with key size, Shor’s algorithm scales polynomially, meaning a quantum computer could factor a 2048-bit RSA key in hours or days rather than billions of years (Classiq, 2026).
For three decades, Shor’s algorithm was a theoretical threat because the hardware required to run it did not exist. The algorithm requires a Cryptographically Relevant Quantum Computer (CRQC)—a machine possessing thousands of “logical qubits” with exceptionally low error rates. As of mid-2026, no such machine exists. However, the timeline for its arrival is violently compressing due to simultaneous breakthroughs in both hardware architecture and algorithmic efficiency.
Recent research has drastically lowered the barrier to entry. While initial estimates suggested breaking RSA-2048 would require 20 million physical qubits, optimisations to Shor’s algorithm have reduced that requirement to fewer than one million, with some experimental protocols suggesting the threshold could drop to around 100,000 qubits (Quanta Magazine, 2026).
This algorithmic efficiency is colliding with rapid hardware scaling. While earlier conservative estimates placed Q-Day in the late 2030s, the credible window has shifted drastically. The U.S. government has mandated that national security systems complete their transition to post-quantum cryptography by 2032, and the Defence Advanced Research Projects Agency (DARPA) has noted that utility-scale, cryptographically relevant quantum computers are likely achievable by 2033 (Bitcoin Suisse, 2026).
The vulnerability gap isn’t just about when the hardware arrives; it is defined by how long it takes to upgrade the world’s infrastructure. Migrating a global enterprise to quantum-resistant lattice-based cryptography is a multi-year logistical nightmare. The telecommunications infrastructure supporting 5G networks, the embedded systems in aerospace platforms, and legacy financial databases cannot simply be patched overnight.
The “Harvest Now, Decrypt Later” paradigm forces a reckoning within global cybersecurity. It is no longer sufficient to secure data against the computing power available today. The intelligence community is acutely aware that the exfiltration phase of the quantum arms race is already underway, happening silently across hijacked routing tables and tapped oceanic fiber.
While the global migration to post-quantum cryptography has begun, it offers no retroactive protection. Data harvested in 2025 or 2026 is permanently compromised, sitting in dark archives, waiting for the hardware to catch up to the math. In this silent arms race, the breach has already occurred; the world is simply waiting for the lock to break.





Leave a Reply