How Quantum Computers Threaten Encrypted Data Collected Today
A sufficiently powerful quantum computer could break several public-key cryptographic systems that are widely used to establish encryption keys and authenticate digital communications. The primary concern is not that quantum computers can decrypt all encrypted data directly. The concern is that they could break the public-key mechanisms used to protect the symmetric keys that encrypt most data in transit and, in some systems, data at rest.
Current quantum computers cannot perform these attacks at the scale required to break widely deployed cryptography. A cryptographically relevant quantum computer would need enough reliable, error-corrected quantum operations to run attacks against public-key systems such as RSA, finite-field Diffie-Hellman, and elliptic-curve cryptography. No one knows when such a system will exist. NIST states that estimates range from years to decades and that the field still faces substantial technical challenges.
The risk exists today because encrypted information can be copied and stored before it can be decrypted. An attacker can record encrypted network traffic, obtain encrypted backups, exfiltrate encrypted databases, archive encrypted files, or preserve protocol transcripts. The attacker does not need to break the encryption immediately. They can retain the ciphertext until a future capability makes decryption feasible. This threat model is commonly called harvest now, decrypt later.
The data most exposed to this risk is data that must remain confidential for longer than the expected time required to migrate systems to post-quantum cryptography and longer than the time until a cryptographically relevant quantum computer may exist. Examples include government and diplomatic communications, defense information, intellectual property, product designs, pharmaceutical research, financial records, medical records, genetic data, long-term identity data, legal files, and critical-infrastructure information.
A normal TLS connection provides a useful example. TLS usually encrypts application traffic with a symmetric algorithm such as AES-GCM. The session keys used by AES-GCM are commonly established through a public-key key-exchange mechanism such as Diffie-Hellman or elliptic-curve Diffie-Hellman. If an attacker records the TLS handshake and encrypted traffic today, a future quantum computer may be able to break the classical public-key key exchange, reconstruct the shared secret, derive the session keys, and decrypt the recorded traffic.
Forward secrecy does not remove the harvest-now, decrypt-later risk when the recorded session relies entirely on a classical ephemeral Diffie-Hellman or elliptic-curve Diffie-Hellman exchange. Forward secrecy protects past sessions if a server’s long-term certificate private key is compromised later. It does not protect recorded sessions if a future attacker can solve the mathematical problem underlying the ephemeral key exchange itself.
The same principle applies to VPNs, SSH, QUIC, IPsec, service-to-service TLS, secure messaging protocols, and other systems that use classical public-key cryptography to establish session secrets. An attacker who can collect the encrypted transcript may not be able to read it today, but the transcript can retain value for future decryption if it protects data with a long confidentiality lifetime. NIST identifies TLS as a major target for post-quantum transition work because of its widespread deployment and exposure to harvest-now, decrypt-later collection.
Data at rest has a different exposure pattern. A database, disk, backup, or archive may use AES-256 or another strong symmetric encryption algorithm. The bulk data encryption may remain comparatively resilient to known quantum attacks, particularly when using sufficiently large symmetric keys. The quantum-sensitive weakness may exist in the key-management layer: for example, if the data-encryption key is wrapped using RSA, released through a classical public-key mechanism, protected by a quantum-vulnerable certificate chain, or recovered through an archived key-exchange process.
Quantum computing is expected to affect public-key cryptography more severely than modern symmetric encryption. Shor’s algorithm threatens the mathematical assumptions behind RSA, Diffie-Hellman, and elliptic-curve cryptography. Grover’s algorithm provides a theoretical speedup for brute-force search against symmetric keys, but NIST states that the practical effect is more limited and that approved symmetric algorithms with at least 128 bits of classical security remain significantly less vulnerable than current public-key systems. AES-192 and AES-256 provide additional margin for long-term protection.
Quantum computers also threaten digital signatures. RSA and elliptic-curve signatures are used to authenticate software updates, firmware, code, certificates, identity assertions, transactions, and signed records. A future attacker capable of breaking the associated public-key systems could potentially forge signatures or impersonate entities protected by quantum-vulnerable signature schemes. This is an integrity and authenticity problem rather than a harvest-now, decrypt-later confidentiality problem, but it requires the same migration planning.
Post-quantum cryptography uses algorithms intended to resist known attacks from both conventional and quantum computers. NIST finalized its first three post-quantum standards in 2024: FIPS 203 for ML-KEM key establishment, FIPS 204 for ML-DSA digital signatures, and FIPS 205 for SLH-DSA digital signatures. ML-KEM is designed to establish a shared secret over a public channel without relying on the RSA or elliptic-curve assumptions threatened by quantum computing.
Post-quantum migration is not a simple replacement of one algorithm name with another. Systems must identify where cryptography is used, which data has a long confidentiality or authenticity lifetime, which protocols depend on classical public-key algorithms, which hardware and software components support post-quantum algorithms, and how larger key, ciphertext, and signature sizes affect network and application behavior. NIST recommends beginning with a cryptographic inventory covering algorithms, keys, certificates, protocols, libraries, hardware modules, systems, and data flows.
A useful priority test is:
Priority = confidentiality lifetime + migration time + likelihood of data capture
Data should be prioritized when it must remain confidential for many years, is likely to be transmitted or stored where an attacker can copy it, and is protected by classical public-key cryptography that will take time to replace. NIST’s transition guidance makes the same practical point: organizations must begin migration before the time required to protect the data and complete the transition exceeds the time until a cryptographically relevant quantum computer becomes available
Post-quantum cryptography cannot retroactively protect ciphertext that an attacker has already collected under quantum-vulnerable key establishment. The objective is to reduce future exposure by migrating the highest-value and longest-lived data flows before those data flows are recorded by an adversary.

Comments