Skip to content
Back to Blog
AI Security

Why someone would steal data they can't even read yet

Adversaries are already stealing encrypted data they can't read, betting on quantum computers to unlock it in a decade.

Sarthhak Kaluuchaa · ·
quantum computing data security encryption professional services

Imagine a thief who breaks into a vault, can’t crack the lockbox inside, and takes it anyway. That sounds irrational. It isn’t, if the thief believes a master key is coming.

That’s the bet nation-state actors and organised criminal groups are making right now with encrypted data. They can’t read most of what they’re stealing today. They’re stealing it anyway, and storing it, because they expect to be able to read it within the decade.

What “harvest now, decrypt later” actually means

The strategy is simple. Collect encrypted data now, while it’s flowing across networks or sitting in backups, and hold it until the tools to break the encryption exist. This isn’t speculative. Security researchers have documented this behaviour for years, aimed at government communications, defence contractors, and increasingly, ordinary businesses whose data has long shelf life.

The encryption doing the protecting today is RSA and elliptic curve cryptography, the math behind most of the internet’s secure connections and most stored file encryption. Both rely on problems that are effectively unsolvable for a classical computer. A sufficiently powerful quantum computer changes that arithmetic entirely.

Estimates for when a cryptographically relevant quantum computer arrives range from 2030 to 2035, with some researchers pointing to earlier. Nobody knows the exact year. What’s not in dispute is the direction: the timeline is closing, not opening.

NIST, the US body that sets cryptographic standards used worldwide, published its first set of post-quantum cryptography standards in 2024. It also maintains a list of algorithms slated for deprecation. Most large enterprises, particularly in finance and defence, have already started migrating. Most small and mid-sized businesses have not, and most haven’t heard this is coming.

Why this matters for a firm like yours

Here’s the part that’s easy to miss. The breach isn’t in the future. It’s happening now, even though the readable data comes later.

A CA firm holds financial records with confidentiality obligations that don’t expire in a year or two. A law firm holds case files, settlement terms, and client communications that stay privileged for the life of the matter and often beyond it. A financial advisory holds portfolio data and personal financial details clients expect to stay private indefinitely.

If any of that data is exfiltrated today, encrypted or not, the confidentiality obligation is already broken the moment it leaves your systems. The fact that it’s unreadable for now doesn’t undo the exposure. It just delays when the client, the regulator, or the opposing counsel finds out.

Most firms in this position have never had to think about cryptography as a business risk. It sat quietly underneath everything, working, and nobody asked questions about it. That’s changing, not because the threat is exotic, but because the shelf life of professional services data is exactly the kind of thing this attack is built for.

What a realistic response looks like this quarter

This isn’t a five-year infrastructure project. It’s a scoping exercise, and most firms can do the first pass in a matter of weeks.

Start with an audit of which data actually needs long-term confidentiality. Client financial records, legal case files, and personal data usually qualify. Marketing materials and internal scheduling usually don’t. Not everything needs the same protection.

Next, find out which encryption algorithms your systems and vendors actually use, and check them against NIST’s deprecation list. Most firms have never asked this question of their software vendors, which means most firms don’t know the answer.

Then prioritise migration to post-quantum algorithms for the most sensitive data stores first, not everything at once. And ask every vendor and SaaS provider you rely on for their post-quantum roadmap. If they don’t have one yet, that’s useful information too.

None of this requires becoming a cryptography expert. It requires someone asking the right four questions before a client, a regulator, or a journalist asks them for you.


A StackGuard audit includes a Future Threat Briefing that covers exactly this: which of your data stores carry long-term confidentiality risk, and what post-quantum migration looks like for a firm your size. It’s one section of a broader report, not a separate sales pitch.

Ready to build systems that scale?

Book a free 30-minute strategy call and we'll map your highest-ROI automation opportunities.