State-Actor HNDL Campaigns: What Is Known and What Is Suspected

In May 2015, US intelligence agencies confirmed that an adversary had exfiltrated 21.5 million security clearance application records from the Office of Personnel Management. The files contained the SF-86 forms completed by federal employees seeking access to classified information: family relationships, foreign contacts, financial history, psychological assessments. Attribution pointed to Chinese state-affiliated actors. At the time of the breach, those records were encrypted in transit and at rest under the cryptographic standards then in use.

The question that rarely appeared in the post-breach analysis: what happens to that archive when a cryptographically relevant quantum computer (CRQC) becomes operational? SF-86 forms are not ephemeral. They carry permanent sensitivity. The intelligence value of that archive does not diminish with time. On the contrary, it compounds: by 2034 or 2038, the officials whose clearance histories were taken in 2015 will be in more senior positions, not fewer.

This is the logic of Harvest Now Decrypt Later (HNDL): collect encrypted data today against the expectation that tomorrow's quantum capability will make decryption feasible. It is not a novel threat concept. What is novel is the weight of public evidence now available to assess how seriously it should be taken, and where the boundary between documented fact and defensible inference actually sits.

What the public record actually says about bulk data collection

NSA BULLRUN and GCHQ EDGEHILL: what was disclosed

The Snowden disclosures of 2013 revealed two systematic programmes for defeating cryptography at scale. The NSA's BULLRUN programme and GCHQ's parallel EDGEHILL operation involved sustained efforts to circumvent, exploit, and in some cases subvert the standards processes that define the cryptography used across the internet. This was reported by The Guardian, ProPublica, and Der Spiegel from June 2013 onwards, working from documents that named both programmes explicitly.

What is particularly relevant here is not the subversion of standards but the collection logic. Both programmes operated on the premise that cryptographic breaking capabilities would mature after collection. Data gathered under protocols that could not be decrypted at the time of collection was retained for future exploitation. The name "BULLRUN" was chosen with deliberate opacity, but the operational doctrine it represented was not: store encrypted traffic now; break it when you can.

This is structurally identical to HNDL. The BULLRUN disclosures confirm that bulk collection of encrypted data for future exploitation was not a theoretical capability but an operational doctrine as of the early 2010s, practised by the US and UK intelligence community. Any analytic assessment of whether adversary states engage in the same behaviour has to start from that baseline.

CISA and NCSC public statements on adversary collection

Successive government advisories have moved from implication to direct statement. The NSA's CNSA 2.0 advisory of September 2022, which mandated migration to quantum-resistant algorithms across US national security systems by 2030-2033, did not simply set a technical timeline. It explicitly stated that adversaries are currently storing encrypted data with the intent to decrypt it once quantum capability matures. That sentence in a National Security Agency advisory is not a speculative threat projection. It is an intelligence assessment.

The NCSC's 2023 Annual Review acknowledged the same collection behaviour from a UK perspective. The document characterised adversary data collection against a quantum decryption future as an active and present concern, not a hypothetical. When GCHQ's national cybersecurity arm describes an adversary behaviour as ongoing, that characterisation reflects access to classified intelligence. It is not extrapolation from open-source reporting.

State-attributed bulk exfiltration: the case evidence

Anthem, OPM, Equifax: what was taken and why it matters

Three breaches from the 2015-2017 period established the operational pattern that HNDL analysis requires: state-affiliated actors exfiltrating large archives of structured personal and administrative data. The data is not immediately exploitable in the way that banking credentials are. It acquires value over a longer horizon.

The Anthem breach, confirmed via US Department of Justice indictment in 2019 (United States v. Fujie Wang et al., Southern District of Indiana), involved 78.8 million records including Social Security Numbers, employment details, and health information attributed to Chinese state-affiliated actors. The Equifax breach of 2017 resulted in 147 million consumer records; a 2020 DOJ indictment (United States v. Wu Zhiyong et al., Northern District of Georgia) named four officers of the PLA 54th Research Institute.

The OPM breach sits in a different category of sensitivity. The 21.5 million records taken include the detailed background investigation questionnaires completed by individuals seeking US security clearances. Director of National Intelligence James Clapper characterised China as the leading suspect at a June 2015 public conference. The Obama administration made a deliberate policy decision not to issue a formal public attribution. These are not records that lose relevance in five years. A comprehensive dossier on someone who held a mid-level clearance in 2015 and now holds a senior one is worth substantially more in 2030 than it was in 2015.

Why these archives are HNDL assets

The data in the Anthem and Equifax breaches was encrypted in transit and at rest under the standards in use at the time: RSA-2048 and ECDSA for key exchange and authentication, AES-128 or AES-256 for symmetric encryption of stored data. RSA-2048 and ECDSA are broken by Shor's algorithm on a CRQC. AES-128 is weakened to approximately 64-bit effective security by Grover's algorithm; AES-256 retains practical security even post-CRQC.

The critical vulnerability is not in the symmetric cipher used to protect stored data. It is in the key exchange mechanism used to establish TLS sessions. A TLS session using ECDH for key exchange, even if the session data was encrypted with AES-256, exposes the session key to retroactive decryption once a CRQC can break the ECDH operation. The session key having been recovered, all data encrypted within that session becomes accessible.

The temporal mismatch is the analytical point that requires emphasis in board-level discussions. The data was collected when decryption was computationally infeasible. It will be decryptable when feasibility changes. The OPM archive's 50-year sensitivity window makes this almost certain to matter. The Anthem health records carry NHS-equivalent retention periods. These are not edge cases in HNDL analysis; they are the central examples.

For organisations conducting their own HNDL exposure assessment, the HNDL risk assessment framework provides a structured methodology for applying Mosca's inequality to specific data categories. The broader question of which pre-2030 encrypted archives carry the highest HNDL exposure is addressed in the context of the 2018-2030 collection window.

Russia, APT collection priorities, and encrypted data

What attribution reporting documents

Threat intelligence reporting from 2021 onwards, including joint advisories from NCSC, CISA, and FBI, has documented sustained exfiltration activity by Russian state-attributed groups against diplomatic, foreign policy, and defence sector targets. APT29, attributed to the Russian SVR, specifically targeted communications at foreign ministries and government departments. The NCSC/CISA/FBI advisory of April 2021 documented the TTPs associated with this activity in detail.

Diplomatic communications and foreign policy deliberations carry classification and retention periods measured in decades. If those communications were transmitted over TLS connections using ECDH key exchange and those sessions were intercepted, the session keys are recoverable by a CRQC. The intercepted data does not expire. The collection priority and the cryptographic vulnerability align in a way that makes the HNDL inference structurally defensible.

Mandiant's M-Trends 2024 report, drawing on Google Threat Intelligence Group attribution data, documented persistent exfiltration activity across government, defence, and energy sector targets by Russian APT groups across multiple years. The pattern of targeting, combined with the retention value of the collected data, is consistent with an intelligence horizon that extends to CRQC timelines. For context on how nation-state quantum investment connects to CNI targeting priorities, see the broader programme analysis. The enterprise security implications of the same programmes are covered in the nation-state quantum programmes: enterprise security analysis.

What is inferred, not confirmed

Intellectual honesty requires stating what the public record does not confirm. No government advisory has named a specific Russian state HNDL programme as an explicitly quantum-targeted collection operation. The collection behaviour documented in APT reporting is consistent with HNDL strategy. Whether Russian state doctrine explicitly frames the collection of encrypted traffic as preparation for post-quantum decryption is not confirmed in any unclassified intelligence assessment.

The inference is defensible; it is not documented. These are different things, and the distinction matters for the credibility of any board-level presentation that cites HNDL risk. Overstatement weakens the argument. The documented behaviours, combined with the rational-actor framework, are sufficient to justify a migration programme without requiring a confession.

The rational strategy argument: Mosca's framing

Mosca's inequality

Michele Mosca of the University of Waterloo's Institute for Quantum Computing formalised the decision rule that converts intelligence assessments into organisational risk calculations. The inequality is: if the security lifetime of sensitive data, added to the time required to complete migration to quantum-resistant cryptography, exceeds the time until a CRQC becomes feasible, the organisation is already at risk. The vulnerability is present now even if the CRQC does not yet exist.

The Global Risk Institute's 2024 Quantum Threat Timeline Report, produced by Mosca and Piani, estimates a 14 to 34 percent probability of a CRQC capable of breaking RSA-2048 within 10 years (by approximately 2034). These are probability-weighted estimates, not engineering guarantees. A lower-bound estimate of 14 percent is not "this will not happen before 2034." For the engineering basis behind those timelines, see the CRQC timeline: when quantum computers become a real threat.

Mosca's inequality is more tractable as a board-level risk tool than most of the slide decks it ends up in. Apply it to three data categories. If any of them return a positive result, migration is already overdue for that category. The data sensitivity lifetime assessment provides the input values for the calculation.

Applying Mosca to the attribution record

An adversary with a 10-20 year intelligence horizon, which is standard for state-level strategic collection, rationally harvests encrypted traffic regardless of whether CRQC timelines are 2033 or 2038. For the logical qubit requirements and timeline calculation behind the 2033-2035 window, see the logical qubit Q-Day timeline calculation. The collection cost is low; the potential payoff is significant; the risk of collection is minimal once the target network has been penetrated. Waiting until CRQC feasibility is confirmed before collecting is not rational from an intelligence collection standpoint. By then, the window for collection may have closed if targets have migrated to quantum-resistant protocols.

Attribution confidence is not a precondition for risk management. The harvesting behaviour is documented across multiple independent sources. The CRQC timeline probability is quantified by the GRI. Mosca's framing converts both into a migration urgency calculation that does not require certainty about adversary intent or capability.

What remains speculative: the honest boundary

What is not confirmed in the public record

Three things cannot be confirmed from open sources. First, no public government advisory has confirmed a specific HNDL programme by name as explicitly targeting post-quantum decryption. The BULLRUN and EDGEHILL disclosures confirm the collection-for-future-exploitation logic; they predate the current quantum timeline discussions. Second, quantum decryption timelines carry substantial uncertainty: the GRI 2024 estimates are probability distributions, not engineering projections. Third, the volume of adversary-archived data that is cryptographically susceptible to future CRQC decryption cannot be independently verified from public sources.

The third point is structurally unfalsifiable from open sources. It will remain an assumption until classified intelligence is made available, which is not a realistic planning horizon. Risk management has to proceed in the absence of that certainty.

Where the inference is defensible

The collection behaviours are documented from independent primary sources: Snowden disclosures, DOJ federal indictments, ODNI public statements, NCSC/CISA/FBI joint advisories. The cryptographic vulnerability is mathematically established: Shor's algorithm breaks RSA and ECC on a CRQC. This is a published mathematical result, not a contested claim. The rational-actor framework closes the logical gap: the inference that state actors with documented collection capabilities and long intelligence horizons will exploit archived encrypted data when CRQC capability matures does not require a confirmed intent document to be a valid risk planning assumption.

Implications for security posture today

Data classification and sensitivity lifetimes

The practical question for security teams is specific, not abstract: which data in your archives was encrypted under RSA or ECDSA-based key exchange, when was it transmitted or stored, and what is its sensitivity lifetime? Health records under UK NHS retention policy (minimum eight years for adults, longer for children's records) sit within the HNDL exposure window if they were transmitted over TLS sessions before ML-KEM migration. MiFID II trading records (five to seven year retention) may be on the boundary. M&A communications with 10-year or longer legal hold requirements are squarely within it. Security clearance equivalent files are permanently sensitive.

This is not a theoretical exercise. It produces a prioritised list of data categories that should drive migration sequencing decisions.

Migration prioritisation

For organisations with long-retention sensitive archives, PQC migration of key exchange mechanisms takes precedence over signature migration. TLS sessions that used ECDH or X25519 for key exchange, even when the session cipher was AES-256, expose the session key to retroactive decryption via CRQC. The session key being recovered, the session data is accessible. Signature schemes (ECDSA, RSA signing) are vulnerable to forgery in a post-CRQC world, but that does not create retroactive decryption of historical data in the same way.

ML-KEM (FIPS 203, finalised August 2024) is the correct replacement mechanism for key encapsulation. It replaces ECDH in TLS key exchange and IKEv2 key agreement. ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) address the signature side, which becomes the second phase of migration.

What security teams can do with this framing

The intelligence-meets-cryptography framing converts what is often presented as a future problem into a present one with measurable parameters. Four practical outputs follow from it. First, a data sensitivity audit: map archives by the encryption standard in use at the time of creation or transmission, not just the current encryption state. Data encrypted under RSA-based key exchange before 2024 carries HNDL exposure regardless of what the archive looks like today. Second, a Mosca calculation applied to the top three data categories by sensitivity lifetime. Third, a board communication that uses the attribution record as a concrete adversary narrative. "A state-attributed actor is storing your encrypted data" is a more tractable board conversation than an abstract quantum timeline. Fourth, migration sequencing that prioritises key exchange over signature migration for long-retention encrypted archives.

QSECDEF's HNDL risk calculator operationalises the Mosca calculation, allowing security teams to run the inequality against their own data retention schedules before constructing a migration business case.


Steven Vaile is Director of Quantum Security Defence.

View on LinkedIn | View Team | QSecDef Events