Today’s encrypted data, such as credentials, may no longer remain confidential in the future because the public-key cryptography protecting it will soon be broken by quantum computers. Although no machine today can break elliptic curve cryptography or RSA, quantum hardware is advancing rapidly and will inevitably change how organizations protect their data. Ciphertext and credentials captured by attackers can now be stored and decrypted as soon as quantum computing catches up.
The Global Risk Institute’s 2025 Quantum Threat Timeline report shows that 51-70% of surveyed security specialists believe a cryptographically relevant quantum computer is likely within 15 years. The threat dates back to 1994, when Peter Shor proved that a powerful quantum computer could efficiently factor large numbers and compute discrete logarithms. However, Shor’s algorithm applies to public-key cryptography, posing no meaningful threat to symmetric encryption like AES-256 or modern hashing.
What makes the quantum threat relevant today is the tactic known as Harvest Now, Decrypt Later, in which an attacker captures encrypted traffic today, stores it, then decrypts it when a quantum computer is available. With a capable quantum computer plausibly available within 15 years, any data intercepted and harvested today should be treated as data already exposed.
Government agencies are setting deadlines around Q-day. NSA’s Commercial National Security Algorithm Suite 2.0 will require new national security systems to start supporting quantum-resistant algorithms starting January 1, 2027, with full quantum resistance by 2035. NIST’s draft IR 8547 deprecates RSA-2048 and ECC P-256 after 2030 and disallows them entirely after 2035. A full enterprise transition could take 5 to 15 years.
Credentials carry major risk because they have long confidentiality lifetimes, often persisting for years. Non-Human Identities (NHIs) like service accounts and API keys are particularly vulnerable as they tend to be long-lived and poorly inventoried. Organizations should take a credentials-first approach to quantum migration: inventory existing cryptography, prioritize risk over size, migrate to hybrid cryptography combining classical and quantum-resistant algorithms, and build for crypto-agility.
In November 2025, Keeper Security began rolling out quantum-resistant cryptography across all client applications, adopting Kyber Hybrid Key Encapsulation Mechanisms (KEM) to help secure vaults from Harvest Now, Decrypt Later and other quantum computing threats.
CVEs: CVE-2026-20245
Companies: Keeper Security, Global Risk Institute, NSA, NIST
Products: Keeper
Events: Q-day
Original source: thehackernews.com