Confirmed: Security researchers describe "harvest now, decrypt later" (HNDL) as an active, ongoing strategy — nation-state adversaries capturing encrypted traffic today specifically to decrypt it once a cryptographically relevant quantum computer exists. Palo Alto Networks' Unit 42 found the fastest quartile of breach intrusions reached data exfiltration in just 72 minutes in 2025, down from 285 minutes in 2024 — attackers are getting faster at the capture stage, which is the stage that matters for HNDL.

Genuinely uncertain: When a quantum computer capable of actually breaking that captured data arrives. Estimates cluster around 2030, but experts diverge meaningfully on the pace.

Worth examining honestly: Your password was never really the target. A password protects a login. HNDL doesn't care about your login — it cares about the encrypted session itself, sitting in an archive, waiting. Changing a password after a breach fixes access. It does nothing for data that was captured in transit years earlier and is simply waiting for the math to catch up.

CIPHER-7's warning has always been about this exact distortion: the security theater of "change your password" while the actual exposure — encrypted archives collected over a decade, sitting in someone else's storage — goes unaddressed because it's not a login problem. It's a cryptography problem, and it's retroactive.

The Door This Opens

The uncomfortable math: any sensitive data you sent under standard encryption more than a few years ago, that still needs to stay confidential today, may already be sitting in an archive somewhere. Post-quantum cryptographic standards were finalized in 2024 — the fix exists. What doesn't exist yet, for most organizations, is the migration.