Desk live·
ForensicPost
Nation-state/Cryptography/File 26-0106

Five National Agencies Confirm Harvest-Now-Decrypt-Later Collection Is Active

Five national agencies have confirmed harvest-now-decrypt-later collection as active and ongoing. For anything that must stay secret for a decade, the deadline has already passed.

Constructed geometry · not a chart of case data
TargetEncrypted traffic in transit
ActorMultiple nation-states
D. Kennedy13 min readConfidence: high3 sources reviewed

CISA, the NSA, the UK NCSC, ENISA and the ACSC have each formally confirmed harvest-now-decrypt-later collection as an active, ongoing operation by multiple nation-state actors. The premise is simple: capture encrypted traffic today, store it, and decrypt it when the capability exists.

This desk is careful with claims about future capability, and this one does not depend on any. The collection is happening now and is confirmed. Whether and when the decryption becomes feasible is a separate question that the collectors are evidently willing to bet on.

The Deadline Is Set By Your Data, Not By The Technology

The framing that matters is not when a quantum computer breaks RSA. It is how long a given piece of information needs to remain confidential.

A session cookie needs minutes. A price negotiation needs months. A patient record, an intelligence source’s identity, a state’s diplomatic traffic, a person’s biometric enrolment — these need decades. For anything in the last category, traffic captured today is already exposed if the capability arrives within its confidentiality lifetime.

Which Is Why The Argument About Timelines Is Beside The Point

Debate about whether a cryptographically relevant machine arrives in five years or twenty is genuinely unresolved, and it is the wrong axis for a defender.

An organisation only needs to ask a question it can answer from its own records: what do we transmit that must still be secret in fifteen years? If the answer is anything, the risk is present-tense regardless of who is right about the timeline.

What This Means For The Files In This Database

The categories this desk has covered with the longest confidentiality requirements are exactly the ones exposed here: biometric registers as in 26-0324 and 26-0217, national identity systems, lawful-intercept infrastructure as in 26-0715, and health records.

None of those can be re-issued when the encryption fails, which is the same structural problem in a different layer.

How we reported this

Compiled from published agency guidance and analysis, listed below. We make no claim about when quantum decryption capability will exist; the confirmed fact is the collection activity. Corrections: corrections@forensicpost.com.

Sources
  1. Harvest now, decrypt later: quantum security riskPalo Alto Networks
  2. Harvest now, decrypt later: a guide to post-quantum cryptographic migrationMedium — Adnan Masood
  3. Post-quantum cryptography: harvest-now readinessServnet UK
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary