up:: 00 Start Here
Is someone stealing my data right now?
You are in the Plain English section
This is written for anyone without a security background, with no jargon and nothing assumed. For the technical detail, the threat modeling, and the full citations, see Harvest Now, Decrypt Later (HNDL).
The short version:
- Possibly, and nobody can tell you for certain about your own data. There’s no way to check.
- What is being taken is a copy. Nothing is broken into, nothing is deleted, and nothing on your phone behaves differently.
- Whoever takes it can’t read it yet. They’re storing it until a machine exists that can.
- Storage is so cheap that keeping it for 10 or 15 years costs almost nothing.
- It only matters for information that’s still sensitive years from now, which rules out most of what you send and rules in things like your medical history and your DNA.
- The U.S. government has said in published guidance that this is something to plan against now.
What does “stealing” mean here?
It means copying, and that difference matters.
When you send a message, it travels across cables and networks owned by other companies before it reaches whoever you sent it to. Along the way it is scrambled, so anyone watching sees nothing readable.
Someone can still write down a copy of that scrambled version as it passes. They haven’t touched your phone, they haven’t signed into your account, and they haven’t deleted anything. Your day is completely normal, and there’s nothing to notice.
That’s the whole event. Someone made a copy of something they can’t read.
Why would anyone keep something they cannot read?
Because they expect to be able to read it later.
The scrambling that protects your message is built on arithmetic that everyday computers can’t undo. A different kind of machine, called a quantum computer, will be able to. Nobody’s built one big enough yet.
So the logic is patient rather than clever. Copy it now while it is unreadable, keep it, and open it on the day the machine exists. Everything saved that way becomes readable at once, going back to whenever the copying started.
Storing that much material is the cheap part. Keeping very large amounts of data costs a fraction of a cent per gigabyte per month, so a person or group willing to wait 10 years pays very little to wait.
Is this a real concern, or is someone selling something?
It’s real, and you don’t have to take a security company’s word for it.
In August 2023, three U.S. federal agencies, CISA, the NSA, and NIST, published joint guidance saying attackers:
“could be targeting data today that would still require protection in the future (or in other words, has a long secrecy lifetime), using a catch now, break later or harvest now, decrypt later operation.”
That’s the government describing the practice in its own document, treating it as a reason to act.
Source: Quantum-Readiness: Migration to Post-Quantum Cryptography, CISA, NSA, and NIST joint factsheet, August 21, 2023.
Which of my information would actually be worth keeping?
Only the things that’ll still matter when someone finally opens them. That’s a much shorter list than people expect.
Ask one question about anything you send: in 15 years, would this still be sensitive?
| Almost certainly worth keeping | Almost certainly worthless |
|---|---|
| DNA and genetic test results | Arguments about dinner plans |
| Fingerprints and face scans | What you watched last night |
| Medical and mental-health records | Most day-to-day messages |
| Fertility and period tracking | Delivery notifications |
| Immigration and court paperwork | Anything already public |
| Financial records tied to long loans | Expired session logins |
The left column has a property the right column doesn’t: you can’t change any of it later. A stolen credit card gets replaced by Friday. Your genome is yours permanently, and it identifies your parents, siblings, and children too, none of whom agreed to anything.
The full catalog, sorted by how long each category stays sensitive, is in What Data Is Vulnerable to Harvest Now, Decrypt Later.
Can I find out whether my data was taken?
No. There’s no service that checks, no notification that arrives, and no way to look.
This is the part that surprises people most, and it follows directly from what actually happened. Since nothing was broken into, there was no incident. With no incident, a company has nothing to report and the law requires nobody to tell you. Every data-breach notification law ever written is built around a break-in that this does not involve.
So the familiar sequence, where a company writes to say your data was exposed and offers you a year of credit monitoring, never begins.
Who is doing it?
Nobody can name a specific group and prove it, and anyone who claims certainty should be asked how they know.
What can be said is that both halves of this are everyday. Copying data as it crosses a network leaves no trace, and storing it’s cheap. Governments have the widest reach because they can see the most traffic, and the low cost means far more actors can afford to participate than most people assume.
More at Store-Now-Decrypt-Later Actor Landscape.
What can I actually do?
Short, honest, and it’s genuinely most of the list.
- Keep your phone, computer, and apps updated. This is the one that matters. The repair arrives through updates, which is why Signal and iMessage users already have protection they never asked for.
- Use a messaging app that has already been upgraded for anything that has to stay private for years. Signal and iMessage have it.
- Delete what you’re finished with. Anything already deleted can’t be copied from you later.
- Think twice before a DNA kit. It can’t be withdrawn, and it enrolls relatives who never consented.
- Ask the places holding your records what their timeline is. Your doctor, your bank, and your insurer hold the categories that actually matter.
- Buy nothing. No product fixes this. Anyone selling a quantum-proof phone, router, or USB stick is charging you for a problem their product doesn’t address.
Questions people ask
Will my bank account be emptied? No. Someone reading a copy of old traffic learns things about you, and it doesn’t hand them access to your money.
Should I stop using the internet? No, and it wouldn’t help. Anything already copied is already copied.
Is my encrypted messaging app enough? It depends on the app. Signal and iMessage upgraded specifically to close this. Apps still using the older method remain copyable.
Are my passwords at risk? Largely no, and the reason’s worth understanding. See Passwords in a Quantum World.
When will the machine exist? Nobody credible names a year. Expert surveys put the chance at roughly 28% to 49% within 10 years and 51% to 70% within 15.
Source: M. Mosca and M. Piani, Quantum Threat Timeline Report 2025, Global Risk Institute / evolutionQ, globalriskinstitute.org.
Where to go next
Go deeper into the technical detail
The technical version of this page: Harvest Now, Decrypt Later (HNDL), which covers threat modeling, urgency ranking, and the full source list. How the protection works in the first place: Foundations MOC, written for security professionals.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.