Hackers stockpile encrypted data for a future quantum breakthrough
Cyber attackers are collecting unreadable databases now in hopes that quantum computers will later make today’s encryption obsolete.
By Hana Yoshida · Markets Reporter
3 min read
Hackers are stealing encrypted data they cannot currently read, expecting future quantum computers to make it usable, Fortune reported. The tactic raises a long-term security risk for banks, cryptocurrency holders and anyone whose private data may remain valuable for years.
The practice is known as “harvest now, decrypt later.” Attackers copy databases today and store them, betting that quantum computing will eventually break common encryption systems that now protect bank accounts, bitcoin and other sensitive information, according to Fortune.
Researchers and investors disagree on when that threat becomes practical. Fortune reported that some observers think quantum computers capable of defeating standard encryption could arrive within a couple of years, while researchers at ARK Invest have said that capability will not arrive before 2044.
Nicolas Sauvage, president of TDK Ventures, told Fortune that hackers are already collecting information on the assumption that quantum tools will later let them decode it. He said the risk depends partly on whether passwords, financial records or other stolen data remain valid when attackers gain the ability to read them.
TDK Ventures, which Fortune described as a $500 million fund, is looking at investments in cybersecurity defenses aimed at quantum-related threats. Sauvage told Fortune that companies are nearing the point where they need to examine quantum security and prepare for the shift before it arrives.
Why unreadable data still has value
Traditional cyberattacks often focus on information that can be used immediately. In a harvest-now operation, the value is delayed: encrypted files may be useless to criminals at the moment of theft, but they could become valuable if future computers can break the protections around them.
Sauvage pointed to Salt Typhoon, a Chinese government hacking operation, as an example of the scale of data collection already under way. NBC News has reported that Salt Typhoon gathered data from at least 200 companies across 80 countries.
The concern is broad because encryption sits underneath much of modern digital life. Fortune cited financial data, private communications, email and cryptocurrency as areas protected by encryption that could face new exposure if quantum computing changes the economics of cracking protected files.
Sauvage told Fortune that, in principle, systems can be broken if attackers have enough time and resources, but current encryption makes many targets uneconomic to attack. He warned that quantum computing could sharply change that calculation by making protected data faster and cheaper to decode.
A seven-year warning
Sauvage estimated to Fortune that the moment when data lacking quantum-resistant protections can be readily decrypted is probably about seven years away. That forecast is more urgent than ARK Invest’s timeline and reflects the uncertainty around when quantum machines will become powerful enough for large-scale attacks.
For companies, the issue is timing. Data stolen today may still matter years from now, especially if it includes long-lived credentials, financial histories or private correspondence. Fortune reported that investors such as TDK Ventures are treating that gap as a market for new defensive technology.
This story draws on original reporting from Fortune.