Skip to content

Education

How encrypted data is harvested (without breaking crypto today)

Harvest-now-decrypt-later does not require breaking RSA today. Adversaries copy ciphertext through paths your security team already tracks — breaches, backups, and archives.

Diagram of HNDL collection vectors.
Why Your Encrypted Data Is Already Being Stolen Watch on YouTube

Key terms

HNDL, ciphertext, CRQC, forward secrecy, ECDH — see definitions on the HNDL hub.

What harvesting means

Harvesting is copying and storing encrypted data — not decrypting it in real time. Storage is cheap; migration takes years. Nation-state and criminal actors treat ciphertext as a long-term asset.

The five collection paths

VectorWhat gets copiedWhy it matters for HNDL
Breach exfiltrationDB dumps, file shares, backup appliancesFastest path in enterprise incidents
Backups & archivesTape, S3 snapshots, email archivesLong retention = long Mosca X
Cloud misconfigurationPublic snapshots, open prefixesNo crypto break required
Bulk transit captureTLS handshakes + ciphertextFuture ECDH break unlocks sessions
Insider / supply chainM&A rooms, subcontractor copiesDecades-long legal holds

TLS nuance for practitioners

Modern TLS 1.3 with forward secrecy means passive wire capture of application data alone is not enough. Adversaries store handshake records (ECDH public keys, certificate chains) plus encrypted payloads. A future CRQC breaks the discrete-log problem in the handshake — then derives session keys.

What to do this quarter

  1. Inventory external TLS, JWKS, SSH, and STARTTLS — free mini-assessment
  2. Tag assets by data shelf-life tier
  3. Quantify Mosca exposure on longest-retained data classes
  4. Export CycloneDX CBOM for GRC integration

Honest scope: Inventory aid, not formal audit. Quantum-vulnerable ≠ broken today.

Related guides

Continue on the Q-Day hub: Harvest now, decrypt later guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-04

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.