Hackers Are Stealing Your Data Now, Waiting For Quantum To Crack It Later. No One Is Ready.
(SeaPRwire) –
By: Lucas Caldwell
Hackers don’t need to crack your encrypted data today to profit from it five or ten years from now. This isn’t some far-off science fiction threat. It’s already a growing tactic tracked by cybersecurity teams across every regulated sector. Most organizations plan for current threats, not attacks that pay off a decade out. That complacency is exactly what bad actors are counting on. I talked to three infrastructure security leads last month. All admitted they hadn’t updated their long-term data storage encryption standards.
The tactic is officially called “harvest now, decrypt later”, and it just landed on mainstream finance and policy radars this week. It fits alongside other top market moving stories in daily roundups: Trump’s proposals that could create a “rigged” stock market, oil back above $90 a barrel, and Iran’s vow to block all oil traffic through the Strait of Hormuz. The core fact is simple. Hackers steal encrypted data they can’t read today, store it, and wait for quantum computing to advance enough to break current encryption standards.
Most of the current public discussion frames this as a future quantum computing problem, not a current hacking problem. That misframing lets organizations off the hook from acting today. Many long-held sensitive data sets, like customer financial records, health data, government documents and intellectual property, retain value for decades. A bank’s customer account data from 2024 will still be valuable for identity theft or blackmail in 2034. Hackers don’t need to hurry. They just need to store the stolen files safely and wait.
The entire technology industry’s incentive structure pushes ignoring this threat. Hardware and software vendors don’t plan products for 10-year risk horizons. They sell annual updates and subscription patches that address only current, known threats. Regulators only mandate audits for current vulnerabilities, not long-term exposure. Organizations see no immediate profit or regulatory benefit to investing in post-quantum encryption upgrades today. So they kick the can down the road, even when they know the risk exists.
Bad actors know this dynamic perfectly. They don’t need large functional quantum computers right now to execute this tactic. They just need enough capital and storage space to hold stolen encrypted data for a decade. Most of these hacking groups are state-sponsored or well-funded criminal networks, with multi-year strategic roadmaps that match the timeline of quantum advancement. They don’t care about quick payouts. They are willing to wait for a much larger payoff when quantum cracks widely used RSA and ECC encryption.
Three out of four Fortune 500 companies storing long-term sensitive data will face a material harvest-now-decrypt-later breach by 2032.
Author bio: Lucas Caldwell, tech opinion leader with millions of X/Twitter followers focused on emerging cybersecurity threats.