August 6, 2026
Sumanth Srirangam

Stolen in Silence. Decrypted on Demand

TL;DR

  • The strategy of collecting encrypted data and waiting to read it later is not new. VENONA proved it in the 1940s. What is new is that the wait is almost over.
  • Nation-state actors across every major intelligence axis are running harvest-now-decrypt-later operations today, confirmed by the US, UK, EU, and Australian cybersecurity authorities.
  • The question is not whether your data has been collected. It is whether, by the time it can be read, there is anything left to read.

In the 1940s, American codebreakers intercepted Soviet cables they had no way to read. They filed them and waited. The cables were protected by one-time-pad encryption, genuinely unbreakable when used correctly. Under wartime pressure, the Soviets duplicated their key material instead of generating it fresh. That duplication became the thread American analysts eventually pulled. The effort, code-named VENONA, ran from 1943 to 1980. Messages sent during the war were still being read decades later. When the plaintext surfaced, it exposed Soviet agents inside the Manhattan Project, including the physicist Klaus Fuchs, and a network of sources across the US government.

Every one of those messages was sent by someone who believed it was safe. They were right about the mathematics. They were wrong about time.

The Strategy Has Not Changed. The Timeline Has.

Harvest now, decrypt later is VENONA running on modern infrastructure. Nation-state actors and sophisticated adversaries are intercepting and storing encrypted traffic today, betting on a future where quantum computers break the RSA and ECC encryption protecting it.

This is not a theoretical concern. At the Vanderbilt Quantum Forum in April 2026, a US national security researcher stated it plainly: "They're capturing the data and they're waiting." The US Department of Homeland Security, the UK's National Cyber Security Centre, Australia's Cyber Security Centre, and the EU's ENISA have all built their post-quantum guidance on the same assumption: the collection phase is already underway. A Booz Allen Hamilton threat assessment put it without hedging: Chinese threat groups will likely collect encrypted data with long-term utility, expecting to eventually decrypt it with quantum computers.

In India, the scale is concrete. In July 2026, roughly 1 TB of Bank of Baroda customer data, Aadhaar scans, PAN cards, KYC records, loan files and branch audits, was published on the dark web. The hacking group TripleX did not even ask for a ransom. They released it for free, immediately. But the identity records in that dump carry a 25-year sensitivity shelf life. The version of this attack that matters is the quiet one: the data collected by a patient adversary who asks for nothing now and waits for the right tool.

The Difference Between Secure Today and Secure Long Enough

VENONA worked because the Soviets were right about the mathematics and wrong about operational discipline. The one-time pad is unbreakable when used correctly. They did not use it correctly.

Most organisations today make a subtler version of the same error. Their encryption is mathematically sound for today's classical computers. But the data it is protecting will still be sensitive in 2035, and NIST's own transition guidance deprecates RSA and ECC after 2030. The FedTech analysis of US federal agencies summarises the position: "Sensitive communications captured in 2026 could be decrypted in 2032. The breach may not be visible when the data is stolen. It becomes visible years later when the encryption protecting it collapses."

That is the gap. Not "is our encryption broken today" but "is our encryption intact for as long as this data has to stay secret."

For most organisations holding KYC records, health data, government communications, and financial histories, the honest answer is: not without action.

What Changes When the Key Cannot Be Copied

VENONA was broken because key material was duplicated. A correctly used one-time pad, with genuinely random, never-repeated key material, remains unbreakable. The lesson is not that encryption failed. It is that key generation and distribution are where the vulnerability lived.

This is precisely the layer quantum key distribution addresses. QKD generates keys from the physical behaviour of photons. Any attempt to intercept a key disturbs the quantum states carrying it, raising the error rate and alerting both parties before the key is ever used. The harvest fails not because the ciphertext is impossible to break, but because the symmetric encryption key is generated and distributed using the principles of quantum physics, making any interception attempt detectable before the key can be used. The adversary never obtains an uncompromised key.

Post-quantum cryptography closes the complementary gap: protecting the data in transit and at rest across the broad enterprise estate with algorithms that have no known quantum attack. Quantum random number generation ensures the entropy feeding every key is physics-based, serving as the root of trust by producing genuinely unpredictable, truly random numbers that close the seed-duplication vulnerability that broke VENONA's operational security.

Together, they address the full chain: the randomness that seeds the key, the key itself, and the data the key protects. Not one of the three in isolation. All three.

The harvesters have always been patient. What has changed is that their wait now has a measurable end. The organisations that act on that fact before the end arrives are the ones whose archives will still be theirs when it does.

Find out whether your data is protected for as long as it needs to be. 

The harvest may have already happened. Find out if you are ready for when the decryption does.

Sources

  1. NSA / CIA, VENONA Declassified Materials : https://www.nsa.gov/Helpful-Links/NSA-FOIA/Declassification-Transparency-Initiatives/Historical-Releases/Venona/smdsearch14707/Venona/smdcat14707/VENONA/
  2. PBS NOVA, Klaus Fuchs and the February 1944 VENONA Cable : https://www.pbs.org/wgbh/nova/venona/inte_19440209.html
  3. The Quantum Insider, Quantum Security: Threats, Solutions, and the Race to Protect Data (Vanderbilt Quantum Forum, April 2026) : https://thequantuminsider.com/2026/04/27/quantum-security-threats-solutions-race-protect-data/
  4. FedTech Magazine, Harvest Now, Decrypt Later: A Federal Quantum Threat : https://fedtechmagazine.com/article/2026/07/harvest-now-decrypt-later-quantum-threat-federal-agencies-perfcon
  5. Booz Allen: https://www.boozallen.com/expertise/analytics/quantum-computing/chinese-cyber-threats-in-the-quantum-era.html
  6. Cloud Security Alliance, Harvest Now, Decrypt Later: Quantum Risk to AI Infrastructure (May 2026) : https://labs.cloudsecurityalliance.org/research/ai-infrastructure-post-quantum-harvest-now-decrypt-later-v1/
  7. State of Surveillance, They're Recording Everything You Send. Quantum Computers Will Read It Later. : https://stateofsurveillance.org/news/harvest-now-decrypt-later-quantum-surveillance-threat-2026/
  8. TechTimes, Bank of Baroda Breach: TripleX Dumps 1 TB of Aadhaar and Account Data for Free : https://www.techtimes.com/articles/321928/20260729/bank-baroda-breach-triplex-dumps-1-tb-aadhaar-account-data-free.htm

Frequently asked questions

What is harvest now, decrypt later?
Is harvest now, decrypt later actually happening today?
Why does the Bank of Baroda breach matter in this context?
What does quantum key distribution do that post-quantum cryptography does not?
Where should an organisation start?

More blogs