A quantum computer able to break today’s public-key encryption does not exist yet. The attack that will use one has already begun. Harvest now, decrypt later means recording encrypted traffic and stolen files today, keeping them, and decrypting them once a cryptographically relevant quantum computer exists. The same attack is also called store now, decrypt later.
Most board discussions of quantum risk start with the wrong question: when will the machine arrive? The more useful question is what an adversary can do today with data it cannot yet read. In June 2026 the United States wrote the answer into an executive order, which names the risk of adversaries collecting information “now, and decrypting it later”. This article explains how the attack works, which of your data is already exposed, what the 2026 evidence says about Q-Day, and six questions a board should put to management this quarter.
What harvest now, decrypt later means
Almost all encrypted traffic on the internet (TLS for websites and APIs, IPsec VPNs, SSH administration sessions) uses public-key cryptography to agree the session keys. Today that means RSA or elliptic curves such as X25519 and P-256. Shor’s algorithm, run on a large enough quantum computer, breaks both. An attacker who recorded the handshake can then recover the session key and read everything that followed.
That makes the attack unusual in three ways:
- The theft and the damage are years apart. Data is taken today; the harm happens when it is decrypted, possibly early next decade. Nothing in your logs will show the second step.
- Forward secrecy does not help. Ephemeral key exchange (ECDHE) protects past sessions if a server’s long-term key leaks later. It does not protect against a quantum computer, which can solve each recorded key exchange directly. Google Cloud’s documentation makes this point explicitly.
- Encryption at rest is mostly not the weak point. Symmetric ciphers such as AES-256 and ChaCha20 are not meaningfully threatened by quantum computers. What is exposed is data that travelled, or was stored, under quantum-vulnerable public-key cryptography.
In brief: Q-Day is the day a quantum computer can break RSA or elliptic-curve cryptography in practice. For harvested data, the exposure is not Q-Day itself but everything recorded before your key exchange became quantum-safe.
How the attack works, step by step

- Access. Gain a position to copy traffic or data: compromised routers and telecommunications infrastructure, cloud or backup accounts, a breached supplier, or a stolen database export that is still encrypted.
- Collect selectively. Storage is cheap, but attackers still choose. The priority is traffic and files that will still be valuable in five to fifteen years: government and defence communications, deal and strategy material, health and identity data, and credentials.
- Store. Keep the ciphertext and the recorded handshakes. Nothing else needs to happen for years.
- Decrypt when able. Once a capable quantum computer exists, recover the session keys from the recorded key exchanges and read the content, or recover private keys and impersonate systems.
Recorded traffic is also a source of secrets that unlock other systems: passwords, API tokens and private keys sent over classical TLS. Cloudflare’s 2026 roadmap notes that even after quantum-vulnerable cryptography is switched off, secrets that were previously exposed still need to be rotated.
Who is positioned to harvest
No government has publicly attributed a specific harvest-now, decrypt-later campaign to a named actor, and vendor claims that such campaigns are “confirmed” deserve caution. What the public record does show is that capable actors already have the access the attack needs.
- In November 2024, the FBI and CISA said PRC-affiliated actors had compromised multiple telecommunications companies, stealing call-records data and compromising the private communications of a limited number of individuals.
- In August 2025, joint advisory AA25-239A described PRC state-sponsored actors, overlapping with the activity tracked publicly as Salt Typhoon, abusing backbone and edge routers worldwide for persistent access to telecommunications, government, transport and military networks since at least 2021. Five Eyes and European partners co-sealed it.
- Europol’s Quantum Safe Financial Forum warned in 2025 that criminals may collect data now to decrypt later, naming M&A plans, trade secrets and long-term investment strategies as examples.
The reasonable conclusion for a board: an actor with persistent access to routers and carriers is positioned to record traffic at scale, and anything it records under classical key exchange has a shelf life that ends on Q-Day.
The quantum threat timeline: what changed in 2026
Estimates of when Q-Day arrives moved sharply between May 2025 and April 2026. None of them is a demonstration, and no cryptographically relevant quantum computer is known to exist. The direction, though, is consistent.
| Date | Source | Finding |
|---|---|---|
| May 2025 | Gidney, Google Quantum AI | RSA-2048 could be factored in under a week with fewer than one million noisy qubits, down from about 20 million qubits in a 2019 estimate |
| March 2026 | Global Risk Institute, Quantum Threat Timeline Report 2025 | 26 experts rated a cryptographically relevant quantum computer within ten years as quite possible (28% to 49%) and within fifteen years as likely (51% to 70%) |
| March 2026 | Google migration timeline | Google set 2029 as the target for its own post-quantum migration |
| March 2026 | Caltech-linked research team | Shor’s algorithm at cryptographic scale with as few as 10,000 reconfigurable neutral-atom qubits, under stated assumptions |
| March 2026 | Google Quantum AI | 256-bit elliptic-curve cryptography could be broken in minutes with fewer than 500,000 physical qubits, about a twentyfold reduction; circuits withheld, claim backed by a zero-knowledge proof |
| April 2026 | Cloudflare | Moved its target for full post-quantum security, including authentication, to 2029 |
Two points matter for risk owners. First, the March 2026 elliptic-curve estimate concerns the algorithms used in today’s TLS key exchange and certificates, not only RSA. Second, the Global Risk Institute survey was published before those March papers, so it does not reflect them, and its experts noted that covert programmes could put the real timeline ahead of public estimates.
Hardware is still short of the requirement. IBM’s roadmap targets a fault-tolerant system with 200 logical qubits by 2029, well below the 1,200 or more logical qubits in Google’s elliptic-curve estimate. Regulators mostly require the risk to be closed between 2030 and 2035, and several of the largest technology companies are working to 2029.
Which of your data is already exposed
The test is simple. If data must stay confidential beyond about 2030, and it has crossed a network under classical key exchange or been encrypted to an RSA or elliptic-curve public key, treat it as potentially harvested.
| Data | Typical confidentiality need | Why it matters |
|---|---|---|
| Health records | 10 years or more; New Zealand requires providers to keep health records for 10 years from the last service | Sensitive for the patient’s lifetime, with heavy regulatory and reputational impact |
| Identity and biometric data | Lifetime | Cannot be reissued once exposed |
| M&A, strategy and investment plans | 5 to 15 years | Named by Europol as priority targets for criminal harvesting |
| Government, defence and critical infrastructure data | Decades | ASD and the NZISM single out highly sensitive and long-lived datasets |
| Contracts, legal privilege, IP and R&D | Life of the contract or patent | Value to competitors and litigants outlives the transaction |
| Credentials, API tokens and private keys | Until rotated | Unlock other systems, so must be rotated after migration |
Traffic that crosses the public internet or a third party’s network is the easiest to harvest. Internal traffic is lower risk because the attacker must first be inside your network, although the router compromises above show that line is not absolute.

What governments and regulators now say
Official warnings have hardened from advice into dates. The most relevant for organisations in Australia, New Zealand, Asia and the Gulf:
| Jurisdiction | Instrument | What it says |
|---|---|---|
| United States | Executive Order 14412, 22 June 2026 | Names the risk of adversaries collecting information now to decrypt later. Post-quantum key establishment on federal high value systems by 31 December 2030 and signatures by 31 December 2031, plus a procurement rule for covered contractors by the end of 2030 |
| United States | OMB memo M-26-15, 24 June 2026 | Prioritises systems holding data expected to remain sensitive in 2030, and re-encryption of long-lived sensitive data |
| Australia | ASD guidance and the ISM | Cites harvest-now, decrypt-later as a reason to act early on highly sensitive data; stop using traditional asymmetric cryptography by the end of 2030 |
| New Zealand | NZISM section 2.4, November 2025 | Agencies should inventory datasets that need long-term protection so they are not protected solely by quantum-vulnerable cryptography; no hard migration year yet |
| United Kingdom | NCSC migration timelines | Discovery and planning by 2028, priority migrations by 2031, complete by 2035; discovery should record each dataset’s lifetime and value to an adversary |
| Singapore | MAS advisory, February 2024 | Quantum computers could put financial transactions and sensitive data at risk; calls for an inventory, senior management awareness and crypto-agility |
| Global financial sector | G7 Cyber Expert Group, September 2024 | Previously intercepted and stored data is at risk, and a capable quantum computer is a real possibility within a decade |
For the full regional deadline calendar, including Singapore’s CSA, the HKMA and the UAE, see our post-quantum cryptography roadmap for APAC banks.
Six questions for the board this quarter
Harvest now, decrypt later changes the order of work. Waiting for a complete cryptographic inventory before acting means another month of data recorded under classical cryptography, every month. These six questions focus management on the controls that stop the exposure growing.
- Which of our data must stay confidential beyond 2030, and where does it travel? Ask for a shelf-life classification of key datasets and flows, with a flag for anything that crosses the internet or a third party’s network.
- What share of our external connections already use hybrid post-quantum key exchange? Modern browsers, Apple’s current operating systems and the major CDNs negotiate the hybrid X25519MLKEM768 exchange by default. The gap is usually on the server side: only about 10% of origin servers behind Cloudflare supported it in February 2026. The answer should come per service, from load balancer or CDN logs.
- Where do we terminate and re-encrypt traffic? CDNs, load balancers, web application firewalls, VPN concentrators and TLS inspection proxies each run their own handshake. Every leg needs to be quantum-safe, not only the first.
- Can we protect traffic in bulk while systems are upgraded? Tunnelling sensitive links over post-quantum encrypted infrastructure reduces exposure now. Cloudflare advises against making an exhaustive inventory a precondition for action.
- What have our critical vendors committed to, in writing? Hybrid key exchange on by default at no extra cost, a dated roadmap for post-quantum signatures, and the ability to switch off classical-only key exchange once clients are ready.
- Do our contracts require it? New and renewing contracts should cover post-quantum key exchange by default, notice and upgrade timeframes for cryptographic deprecations, disclosure of the supplier’s cryptographic inventory, and a right to test.
Key exchange is the part that closes harvest-now, decrypt-later, and it is often a configuration or library change. Signatures and certificates take longer, and the US executive order leaves only a year between the two deadlines, so start that programme in parallel. For how to test and evidence post-quantum TLS, see post-quantum TLS and hybrid key exchange on GRCLens; for running the wider migration as a governed programme, see post-quantum readiness as a GRC programme.
Related reading
- Post-quantum cryptography roadmap for APAC banks
- Board cyber risk KRIs and quarterly reporting
- Zero trust security in 2026
Frequently asked questions
Can quantum computers break encryption today?
No. No cryptographically relevant quantum computer is known to exist. The concern is that data recorded today can be decrypted once one does, which is why regulators are setting migration dates between 2030 and 2035 now.
What is Q-Day?
Q-Day is the informal name for the day a quantum computer can break RSA and elliptic-curve public-key cryptography in practice. Google and Cloudflare are working to a 2029 migration target, and most government deadlines fall between 2030 and 2035.
Is harvest now, decrypt later a real threat?
Governments treat it as one. The US, Australian, UK and New Zealand cyber agencies all cite it as a reason to migrate early, and the June 2026 US executive order names it directly. No specific campaign has been publicly attributed, but capable actors are known to hold persistent access to telecommunications networks.
Is store now, decrypt later different from harvest now, decrypt later?
No. Store now, decrypt later, harvest now, decrypt later and catch now, break later all describe the same attack.
Do we need to replace AES-256?
Generally no. Symmetric encryption such as AES-256 is not meaningfully threatened by quantum computers. The priority is the public-key cryptography used to agree and protect keys, especially key exchange in TLS, VPNs and SSH.
What is quantum-safe encryption?
Encryption built on algorithms believed to resist quantum attack, such as NIST’s ML-KEM (FIPS 203). Today it usually means hybrid key exchange, which combines ML-KEM with a classical algorithm so the connection stays safe as long as either one holds.
How Security Solution Consultants can help
Security Solution Consultants helps boards and security teams across Australia, New Zealand, Singapore, Malaysia and the Gulf close the harvest-now, decrypt-later gap. We classify data by shelf life, measure how much of your external traffic already uses hybrid post-quantum key exchange, find the termination points and suppliers holding you back, and write the vendor questions and contract clauses that make post-quantum protection a requirement rather than a request.
Our security compliance team aligns the work with ASD, NZISM, MAS and NCA expectations, and GRCLens keeps the data register, risks, supplier commitments and evidence in one place. Talk to us about a quantum exposure assessment.


