up:: What’s At Risk

Will anyone ever tell me if it happens?

No. Not now, not when the data is collected, and not when it’s eventually read.

That’s the single strangest feature of this whole subject, and it’s the one people find hardest to accept, because every other data problem in modern life comes with a letter in the post and a year of free credit monitoring.

This one has no letter, because under every framework that exists, nothing happened.

The short version:

  • Copying scrambled data breaks nothing, so no alarm fires and no tool detects it.
  • With no incident, a company has nothing to report and no law requires anybody to tell you.
  • The familiar sequence of breach letter, credit monitoring, and apology never begins.
  • There’s no service that checks, and no way to look.
  • The same absence is why this stays out of the news, since there are no filings to count and no victim totals to report.

Why is there nothing to notice?

Because of what actually happens.

When someone copies scrambled data as it crosses a network, no file is deleted, no account is accessed, no password is changed, and no system behaves differently. Your phone works. Your bank works. Your doctor’s portal works. Nothing on your side of the connection has any way to know a copy was made.

Compare that with the breaches you’ve been notified about. Those involve someone getting into a system: logging in, escalating access, moving data out. Those actions leave traces, trip alarms, and get discovered, sometimes months later, and that discovery is what triggers the letter.

Copying traffic in transit produces none of those traces, because it’s passive. Nothing is entered and nothing is taken from anywhere. A duplicate is made of something already traveling in public.

How does this compare to a breach you’d be told about?

An everyday data breachData copied for later decryption
What happensSomeone gets into a systemA copy is made of traffic in transit
Traces leftLogins, access logs, data moving outNone
Who noticesThe organization, eventuallyNobody
Is there an incident?YesNo
Notification law applies?YesNo
Do you get a letter?Yes, eventuallyNever
Can you check?Breach-notification servicesNo way to look

Why doesn’t the law cover it?

Because every breach-notification law ever written is built around an incident, and there isn’t one.

The structure is consistent worldwide. An organization suffers unauthorized access to personal data, determines the scope, and notifies affected individuals and a regulator within a defined period. Each step depends on the first one.

Here, the organization holding your data was never accessed. Its systems are fine. It has nothing to detect, nothing to investigate, and nothing to disclose, so no obligation attaches to anybody. That’s not a loophole someone exploited. It’s a category the law doesn’t contemplate.

Which means the accountability question is genuinely open, and it’s covered at What isn’t legislated yet?

Can I check whether my data was taken?

No, and it’s worth being direct about that.

There’s no service to query, no dark-web scan that helps, no notification that arrives, and no forensic step you could take. Nobody, including a security professional working full time on your behalf, can determine whether a particular person’s traffic was copied.

The best any honest source can give you is a planning assumption: information with a long secrecy life that has crossed networks over the past several years should be treated as possibly collected and unprovably so.

That’s uncomfortable, and it’s the accurate answer.

When the data is finally read, will I find out then?

Probably not, and history is unusually clear about this.

Every major cryptographic break in the historical record stayed secret for as long as it was useful, often for decades, while the people relying on the broken system kept using it. Whoever reaches this capability first has strong reasons to say nothing and read quietly.

Full treatment at What does history tell us about broken codes?

What you might eventually notice is a consequence rather than a cause: information turning up somewhere it shouldn’t be, with no obvious explanation of how it got there.

Why does this keep out of the news?

This part is worth understanding, because it explains why you’ve probably never read about it.

Journalism finds data-privacy stories through the machinery of disclosure. A company files a notification, a regulator publishes an enforcement action, a class action gets filed, a victim count gets reported. Every one of those artifacts exists because an incident happened and someone was required to say so.

Here there are no filings to count, no totals to report, no company statement to quote, and no identifiable victim to interview. The story is real and it produces none of the evidence that normally makes a story reportable.

That’s also why the coverage that does exist tends to focus on future machines rather than present collection. The machine is a thing you can photograph.

Questions people ask

So how does anybody know this is happening at all? Government agencies have said so in published guidance. Three U.S. federal agencies described attackers targeting data today for later decryption, in a document anybody can read. The mechanism is also cheap and passive enough that expecting it is more reasonable than expecting otherwise.

Source: Quantum-Readiness: Migration to Post-Quantum Cryptography, CISA, NSA, and NIST joint factsheet, August 21, 2023.

Should I assume I’m affected? Assume that anything of yours with a long secrecy life may have been collected, and put your attention on decisions still in front of you rather than on ones already made.

Is there any monitoring service worth paying for? Not for this. Anything sold as detecting or preventing it is selling something that can’t work.

Would my bank know? No. The bank’s systems weren’t touched either.

Does that mean nobody is accountable? Under current law, largely yes, and that’s a gap rather than a settled position.

Where to go next

Go deeper into the technical detail

The technical treatment is Harvest Now, Decrypt Later (HNDL) and The No-Warning Problem.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.