October 9, 2026

Hackers are stealing your data today to read it in 2029

Dark room setup with code displayed on PC monitors highlighting cybersecurity themes.

Most New Zealand boards still file quantum computing under science fiction. The people selling them security are now telling them the deadline is roughly three years away, and the uncomfortable part is that the damage may already be done.

Senior Fortinet executives were in the country this week briefing health, finance, energy and utilities operators. Their message was blunt. AI and quantum computing together will make easy work of decrypting most existing digital devices and systems somewhere between 2029 and 2030 unless they are upgraded. “What we are particularly worried about is infrastructure,” said senior vice president Filippo Cassini.

It would be easy to dismiss this as a vendor drumming up demand. That would be a mistake. The warning lines up with government, academic, banking and governance sources that have no product to sell.

The deadline moved five years closer

The old working assumption was that cryptographically relevant quantum machines would arrive around 2035. Fortinet vice president of product management Wei Ling Neo says heavy AI-driven investment has pulled that forward to “29 and 2030”, and that organisations are so busy chasing AI they have not inventoried the infrastructure and data they hold.

The technical basis is not in dispute. Back in 2023, a University of Auckland report concluded that quantum computers will break essentially all public key encryption schemes currently in use. That covers RSA and elliptic curve cryptography, the plumbing beneath online banking, secure email, payment systems and government data. The only real argument is about the date.

The breach you already had

The reason this belongs on a board agenda now is a tactic called harvest now, decrypt later. Criminals and state actors copy encrypted data today, store it cheaply and wait. Otago University’s Professor David Hutchinson, who sits on an OECD quantum advisory panel, calls it “scary”, noting anything sent now might not be secure in five years.

Brandon Hutcheson, director of quantum at HSO, puts it more vividly in an Institute of Directors analysis: “It’s like people stole the safe and can’t get in, but in the next two years there will be tools available to crack all the safes.” His point is that quantum reverses the usual cyber-risk model. The point of failure and the point of impact are no longer the same event. A breach a company disclosed, insured and moved on from in 2024 could become a fresh privacy disaster in 2030.

Citi Institute made the same case in January 2026, arguing that from a risk perspective Q-Day “is already here” because data stolen today can be decrypted later. Any business holding health records, financial ledgers, identity documents, legal files or intellectual property that must stay confidential for a decade should treat its encryption as having an expiry date.

Severity is rising even as reports fall

The local numbers back the urgency, with a twist. The NCSC’s latest threat report shows total incident reports fell from 5,995 to 4,673 in 2025/26, and direct financial loss dropped to $23.8 million. But four incidents hit the highly significant C2 tier for the first time in five years, and 162 nationally significant incidents were linked to criminal or financially motivated actors, up 18%. The report also warns frontier AI can now find zero-day vulnerabilities, the double-edged sword Fortinet describes.

The government’s own Cyber Security Strategy, released in February 2026, warned that quantum could “turn today’s secure communications into tomorrow’s open books” within the strategy’s timeframe. Yet the Government Chief Information Security Officer has told Treasury that agencies are not dedicating enough time or resourcing to prepare. The rhetoric is ahead of the budget line.

This is a directors’ duty question now

Spectrum Consulting chief executive Marty Bennett describes post-quantum cryptography as a pressing enterprise liability issue rather than a futuristic roadmap item. Once a risk is this well documented, “we didn’t know” stops being a defence. Foreseeable and quantifiable is exactly the territory where directors get asked hard questions after the fact.

The migration is not a patch. Citi’s analysis noted it involves re-engineering interfaces and authentication layers, retraining staff and multi-year programmes across thousands of applications. In 2025, QuintessenceLabs founder Dr Vikram Sharma told the IOD that large organisations typically need three to five years to understand the problem, pilot solutions and integrate them. Do the maths. A board starting today lands close to the 2029-2030 window. A board starting in 2028 does not.

What smart businesses do first

The practical steps are unglamorous. Inventory what encrypted data you hold and how long it must stay secret. Ask every software and hardware vendor for a post-quantum upgrade path before signing the next contract, because buying non-upgradable kit now is buying a future write-off. Exporters should watch the European Commission’s signalled mandatory software-update commitments for digital products from 2030, which will flow down supply chains.

There is upside here too. With public agencies admitting they are behind, private firms that can demonstrate post-quantum readiness will have a genuine edge when tendering for health, finance, energy and government work. The firms that move first will not just avoid the bill. They will get paid for being ready when everyone else is scrambling.

Sources

Reader Poll · 5 questions

Do you agree or disagree with the following?

Community

Join the discussion

Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.

Create a commenter account

Enter the name you want shown publicly and your email. We will email you a password-set link; you cannot comment until you use it.

Your email is used for sign-in and account security. It is not published with comments.

Subscribe for weekly news

Subscribe For Weekly News

* indicates required