What is a "Harvest now, decrypt later" (Y2Q) attack?
Attackers record encrypted data today, planning to decrypt it once quantum computers can break today's crypto.
* Harvest-now-decrypt-later: capture ciphertext today, store it, then decrypt once a quantum computer arrives — which is why long-secrecy data drives the move to PQC. *
Even if you can't read intercepted ciphertext now, you can store it and wait. When sufficiently powerful quantum computers arrive ("Y2Q" — Years to Quantum), algorithms like RSA and ECC could be broken, retroactively exposing everything harvested.
Why it's a today-problem, not a tomorrow-problem: data with a long secrecy lifetime (medical records, state secrets, biometric data) that's stolen now is already at risk. This drives the move to post-quantum cryptography (PQC) — NIST standardised the first PQC algorithms (e.g. ML-KEM/Kyber) in 2024.
Tip: This specifically attacks confidentiality across time — the one CIA goal where a violation can stay invisible for years.
Go deeper:
Harvest now, decrypt later (Wikipedia) — defines the HNDL / Y2Q strategy, the decades-long risk to health and diplomatic data, and the PQC migration.
NIST FIPS 203 — ML-KEM — the finalised post-quantum key-encapsulation standard (ML-KEM/Kyber, Aug 2024) that answers this threat.