Harvest Now, Decrypt Later: The Attack That Has Already Succeeded

Adversaries are stockpiling encrypted traffic and archives today in the expectation that future quantum or hybrid cryptanalysis will open them years from now. This report examines why harvest-now, decrypt-later is the attack that has already succeeded, why long-lived secrets — health, state, intellectual property — are a present-day weapons issue rather than a future one, and why post-quantum migration is the single most consequential defensive action available in 2027.
The Attack That Has Already Succeeded
Most cyber attacks are legible in time. They begin at a moment, they proceed through a sequence of steps, and they end — in success or failure — within a window that the defender can observe and respond to. The defender's entire incident-response apparatus is built around this temporal structure: detect the intrusion, contain it, eradicate it, recover. The attack is an event, and the event has a before and an after.
The harvest-now, decrypt-later attack is not legible in this way. It is an attack that has no end, because it has not yet succeeded. It is an attack that is, from the defender's perspective, indistinguishable from passive collection — the routine interception of encrypted traffic that any intelligence service has always done. The attack consists of storing that traffic, indefinitely, against a future decryption capability that does not yet exist. The attack succeeds not when the traffic is collected, and not when it is stored, but at some unknown future date when a cryptanalytic capability — a cryptographically relevant quantum computer, or a hybrid classical-quantum technique, or a mathematical breakthrough against the specific algorithm in use — makes the stored ciphertext readable.
The temporal inversion is the defining feature. The collection happens now. The exploitation happens later — perhaps years later, perhaps decades. The attack is complete, from the attacker's perspective, the moment the ciphertext is safely stored. Everything that follows is patience. The defender, meanwhile, cannot point to a moment of compromise, because the compromise is not a breach of systems but a future breach of confidentiality, separated from its cause by a gap of years.
This is why harvest-now, decrypt-later is the attack that has already succeeded, even though no secret has yet been read. The success is in the stockpile. And the stockpile is the present-tense fact that makes this a present-day weapons issue, not a future one.
What Gets Harvested
The technical scope of what can be harvested is, in 2027, essentially all encrypted traffic that an adversary can intercept. The practical scope is narrower, because not all encrypted traffic is worth storing for a decade. The attacker's selection is governed by a calculation: which stored ciphertexts, once decrypted, will be valuable enough to justify the cost of storage and the wait?
The answer is determined by the half-life of the secret — the period over which the information remains sensitive, valuable, or actionable. A banking transaction authorization code that expires in sixty seconds has a half-life too short to matter. A diplomatic cable discussing a negotiation that will conclude in six months has a half-life of months. A patient's complete medical record has a half-life of decades — the record describes a person's health history, and that history remains sensitive for the person's lifetime. A state's classified assessment of a rival's military capabilities has a half-life of years to decades, depending on how slowly the underlying capabilities change. A company's intellectual property — the design of a product that will be sold for ten years, the formula of a compound that will be manufactured for twenty, the source code of a platform that will run for fifteen — has a half-life that matches the commercial life of the asset.
The harvest is selective, and the selection criterion is the half-life. The attacker stores the traffic that will still matter when the decryption capability arrives. This means the harvest is not a random sample of the internet's encrypted traffic. It is a curated archive, built by an adversary who has thought about which secrets will still be valuable in five, ten, or twenty years, and who is collecting accordingly.
The Three Categories of Long-Lived Secrets
The traffic that passes the half-life test falls, broadly, into three categories, each of which presents a distinct present-day weapons issue.
Health data. A patient's medical record is among the longest-lived secrets in existence. The conditions, diagnoses, genetic information, and treatment history in a record compiled in 2027 will still be sensitive in 2047, when the patient may be a public figure, a candidate for a position of trust, a party to a legal dispute, or simply a person whose privacy is entitled to protection. Health data harvested today is a future leverage asset — a stockpile of personal vulnerability that can be used for blackmail, for influence, for discrimination, or for the simple commercial value of the information. The half-life of health data is the patient's lifetime, which means the harvest-now window captures essentially all of it.
State secrets. Classified assessments, diplomatic correspondence, intelligence reports, and military planning documents have half-lives that range from years (tactical assessments that expire with the situation they describe) to decades (strategic assessments, treaty negotiations, weapons program details). The state-secret harvest is the classic target of the harvest-now attack, because the value of the information is high, the half-life is long, and the interceptor is typically a rival state with the patience and the storage to wait. A diplomatic cable harvested in 2027 and decrypted in 2037 may still reveal the source of a still-sensitive negotiation, the identity of a still-active asset, or the terms of a still-relevant agreement.
Intellectual property. The design of a next-generation chip, the formula of a proprietary material, the training data and weights of a valuable AI model, the source code of a long-lived software platform — these are secrets whose value persists for the commercial life of the asset, which can be a decade or more. IP harvested today is a future competitive asset: a design decrypted in five years can be manufactured by a rival who did not bear the cost of designing it; a model decrypted in three years can be replicated by a competitor who did not train it. The harvest-now attack against IP is, in effect, a delayed theft — the stolen goods are delivered not when they are taken but when they are decrypted.
The Quantum Horizon and Its Misuse
The technical premise of the harvest-now attack is the future arrival of a cryptanalytic capability that can break the public-key algorithms in use today. The specific capability most often discussed is a cryptographically relevant quantum computer — a quantum machine capable of running Shor's algorithm at a scale sufficient to factor the keys used in RSA and elliptic-curve cryptography. The timeline for this capability is uncertain. Estimates range from a few years to several decades, and the uncertainty is itself a feature of the threat: the attacker does not need to know when the capability will arrive, only that it will.
This uncertainty has produced a dangerous complacency in the defensive discourse. The argument is made that, because the quantum horizon is uncertain and possibly distant, the harvest-now threat is a future problem, to be addressed when the capability is closer. This argument is wrong, and the way it is wrong is the core of the present-day weapons issue.
The argument is wrong because it conflates the time of the exploit with the time of the vulnerability. The exploit — the decryption of the stored ciphertext — is in the future. The vulnerability — the collection and storage of the ciphertext — is now. Every day that traffic is transmitted under algorithms vulnerable to future cryptanalysis, the stockpile grows. The defender who waits for the quantum horizon to address the threat is waiting to act on a vulnerability that is being exploited every day, in the only sense that matters for the future: the ciphertext is being accumulated.
The correct temporal framing is not "when will the quantum computer arrive?" but "how much ciphertext will be in the stockpile when it arrives?" The first question is about the future. The second is about the present, because the answer is determined by what is transmitted today, tomorrow, and every day until the capability materializes. The harvest-now attack is a present-day weapons issue because the weapon — the stockpile — is being assembled now. The future decryption is merely the detonation.
The Hybrid Threat
The quantum horizon is not the only decryption path that matters. A second, nearer threat is the hybrid cryptanalytic attack, in which a quantum computer of limited capability is combined with classical computation to break keys that neither could break alone. Hybrid attacks reduce the quantum resources required, which means they arrive earlier than a full-scale quantum break. The defender who plans for the full quantum horizon may be surprised by a hybrid break that arrives years before it.
A third threat is the mathematical break — a classical algorithmic advance that weakens or breaks a specific public-key system without any quantum involvement. The history of cryptography is a history of algorithms that were believed secure until they were not. The harvest-now attacker does not need to wait for quantum computing if a classical advance against the algorithm in use arrives first. The stockpile is agnostic to the decryption method. It waits for any capability that opens it.
The Asymmetry of Patience
The harvest-now attack exploits an asymmetry between the attacker and the defender that is unusual in cyber conflict: the asymmetry of patience.
In most cyber attacks, the attacker is under time pressure. The intrusion must be detected before the objective is achieved, the malware must execute before it is caught, the exfiltration must complete before the alarm. The defender's speed of detection is a meaningful defense, because the attacker's window is limited.
In the harvest-now attack, the attacker is under no time pressure. The collection is passive. The storage is indefinite. The decryption is future. The attacker can wait years, or decades, because the stockpile does not decay. The defender's speed of detection is irrelevant, because there is nothing to detect — the collection is indistinguishable from the normal interception of traffic, and the storage is invisible to the defender whose traffic has been stored.
This asymmetry inverts the usual logic of defense. The defender cannot rely on detection, because the attack is not detectable. The defender cannot rely on response, because there is no incident to respond to. The only defense is prevention — ensuring that the traffic, if intercepted and stored, cannot be decrypted by any future capability. This is the logic of post-quantum cryptography: replace the algorithms that are vulnerable to future cryptanalysis with algorithms that are believed resistant, so that the stockpile, when the capability arrives, is worthless.
The asymmetry of patience means that the defensive timeline is not aligned with the offensive timeline. The attacker's timeline is long — collect now, decrypt later. The defender's timeline must be short — migrate to resistant algorithms before the stockpile grows further. The defender who waits for the quantum horizon is accepting that every day of waiting adds to the stockpile that the future capability will open. The defender who migrates now is reducing the stockpile that any future capability can exploit.
Why Long-Lived Secrets Are a Present-Day Weapons Issue
The framing of harvest-now, decrypt-later as a future problem rests on the assumption that the weapon — the decryption capability — is what makes the attack a weapons issue. This is a misunderstanding of where the weapon is. The weapon is the stockpile. The stockpile is being built now. The long-lived secrets that fill it — health, state, IP — are being captured now, and their capture is the act that constitutes the weapons issue.
Consider the three categories in this light.
A health record harvested in 2027 is a weapon in 2027, even if it cannot be read in 2027. It is a weapon because it is a stored vulnerability — a future leverage asset that the attacker now possesses, in encrypted form, and that the defender can no longer protect. The defender's opportunity to protect that record ended when it was transmitted and intercepted. The future decryption is the exploitation of the weapon, not the creation of it. The weapon was created at the moment of harvest.
A state secret harvested in 2027 is a weapon in 2027 for the same reason. The diplomatic cable, once intercepted and stored, is a future intelligence asset that the originating state can no longer recall, re-encrypt, or protect. The cable's value may not be realized for a decade, but the loss of control over the secret is immediate. The weapons issue is the loss of control, and the loss of control is present-tense.
Intellectual property harvested in 2027 is a weapon in 2027 because it is a delayed theft in progress. The design, the formula, the model, the source code — once intercepted and stored, is a future competitive asset that the originator can no longer exclusively control. The theft is not complete — the IP cannot yet be used — but the conditions for the theft's completion have been established, and the originator cannot undo them.
In each case, the weapons issue is present, not future. The stockpile is the weapon. The stockpile is being built now. The long-lived secrets that fill it are being lost now. The future decryption is the detonation of a weapon that has already been assembled.
The Defensive Imperative
The defense against the harvest-now attack is not detection, response, or recovery. It is migration. The traffic that is transmitted under post-quantum-resistant algorithms cannot be opened by a future quantum capability, and so it is not worth harvesting. The traffic that continues to be transmitted under vulnerable algorithms is the stockpile, and every day it continues to be transmitted is a day the stockpile grows.
This makes post-quantum migration the single most consequential defensive action available in 2027, and it makes the pace of migration the single most consequential metric of an organization's security posture against this threat. An organization that has not begun migrating its long-lived secrets to post-quantum-resistant algorithms is, with respect to those secrets, effectively transmitting them in the clear to any adversary with the patience to store and wait.
The migration is not trivial. Post-quantum algorithms are newer, less studied, and in some cases less performant than the algorithms they replace. Key establishment, digital signatures, and authenticated encryption must all be migrated, and the migration must be done without introducing vulnerabilities in the transition. Hybrid schemes — which combine a classical and a post-quantum algorithm, so that the ciphertext is secure if either algorithm holds — are a prudent intermediate step, but they are intermediate, not final. The final state is a cryptographic infrastructure in which no traffic of long-lived secrets is transmitted under algorithms vulnerable to future cryptanalysis.
The organizations that should be most concerned are those that hold the longest-lived secrets: health systems, whose patient records will be sensitive for decades; government agencies, whose classified information will be sensitive for years to decades; and technology companies, whose intellectual property will be valuable for the commercial life of the asset. For these organizations, the harvest-now threat is not a future concern to be scheduled. It is a present loss to be stopped.
Conclusion
The harvest-now, decrypt-later attack is the attack that has already succeeded. Its success is the stockpile — the growing archive of encrypted traffic that an adversary is accumulating today, against a future decryption capability that will arrive on an uncertain but inevitable timeline. The long-lived secrets in that stockpile — the health records, the state secrets, the intellectual property — are weapons in the present tense, because their capture is the act that constitutes the loss, and the capture is happening now.
The framing of this threat as a future problem, to be addressed when the quantum horizon is nearer, is a dangerous error. It confuses the time of the exploit with the time of the vulnerability, and in doing so it accepts the continued growth of the stockpile. The correct framing is the opposite: the vulnerability is now, the exploit is later, and the only defense is to stop transmitting the stockpile. The migration to post-quantum-resistant cryptography is not a preparation for a future threat. It is the response to a present one — the response that prevents today's traffic from becoming tomorrow's decrypted weapon.
The pipeline is running. The dashboard is green. The stockpile is growing. And the question for 2027 is not when the decryption capability will arrive, but how much of the stockpile will be waiting for it when it does.
This dossier is part of the CyberArmory 2027 educational catalog. No live weapons are deployed. Every scenario is a controlled educational simulation designed to build pattern recognition and improve incident response readiness.
This report was compiled by the CyberArmory 2027 Research Collective as part of an educational dossier on speculative future cyber warfare technologies. No live weapons are deployed. Every scenario is a controlled educational simulation designed to build pattern recognition and improve incident response readiness.





