up:: The Threat MOC
Is Harvesting Encrypted Data an Act of Cyber Conflict?
Harvesting encrypted traffic has every characteristic that recently persuaded governments to treat network pre-positioning as something beyond espionage: the activity is silent, it causes no present damage, and its entire significance lies in an act the collector intends to perform later. States made that doctrinal move in 2024 for intrusions into critical infrastructure. They have not made it for cryptographic harvesting, which is structurally the same shape and is happening at far greater scale.
My argument is that the gap is a vocabulary problem rather than a considered judgment. The frameworks that would govern this were written around damage, and harvesting produces none until the moment it produces all of it.
The short version:
- The cyber norms are damage-based. The UN’s critical-infrastructure norm turns on activity that “intentionally damages” or “otherwise impairs” infrastructure, and harvesting does neither.
- Peacetime collection is not prohibited by any general rule of international law, so espionage framing leaves harvesting entirely unregulated.
- The doctrine has already made this exact move once. In February 2024, CISA, the NSA, and the FBI assessed that Volt Typhoon’s behavior was “not consistent with traditional cyber espionage or intelligence gathering operations” because the intent was deferred disruption.
- Nothing was stolen in that case. The agencies noted the actors “do not exfiltrate data,” and judged the activity by what it would enable later.
- Harvesting is the same shape with the arrow reversed: data is exfiltrated, and the capability to use it arrives later instead of the intent.
Think of two burglars. One breaks into a building, takes nothing, learns the alarm system, and leaves a door unlocked for a night that may never come. The other copies every document in the safe, in a language nobody alive can read, and waits for the dictionary to be invented. Governments have decided the first one is doing something more serious than casing the place. They have said nothing at all about the second.
What actually counts as an act of cyber conflict?
There’s no single definition, and the closest thing to an agreed standard is the set of voluntary norms of responsible state behavior adopted through the UN Group of Governmental Experts process. Read them closely and the organizing concept is consistently harm.
The critical-infrastructure norm is the clearest case:
“A State should not conduct or knowingly support ICT activity contrary to its obligations under international law that intentionally damages critical infrastructure or otherwise impairs the use and operation of critical infrastructure to provide services to the public.”
Source: UN GGE agreed text, reproduced in ASPI, The UN norms of responsible state behaviour in cyberspace, March 2022, hosted by UNODA, norm (f).
Two verbs carry that norm: damages and impairs. Both describe an effect on the target at the time of the act. The accompanying guidance reinforces it, explaining that such activity “can have cascading domestic, regional and global effects,” “poses an elevated risk of harm to the population,” and “can be escalatory, possibly leading to conflict.”
The other norms follow the same logic, addressing incident response, territorial responsibility for wrongful acts, supply-chain integrity, and vulnerability disclosure. Every one is oriented toward damage that has occurred or is occurring.
Why doesn’t harvesting trigger any of it?
Because at the moment of the act there’s nothing to point at.
- Nothing is damaged. Recording ciphertext in transit leaves the target’s systems exactly as they were, and no service is impaired.
- Nothing is intruded upon. Passive collection touches no system belonging to the victim, so even framings that rest on unauthorized access find no access to object to.
- Nothing is detectable. The target cannot know it happened, which means no incident is reported, no response is triggered, and no state practice accumulates around it. See The No-Warning Problem.
- Espionage is unregulated anyway. Peacetime intelligence collection is not prohibited by any general rule of international law, so the framing most people reach for is the one that guarantees no consequence.
- The harm arrives years later, detached from the act, by which point attribution has evaporated and the collection is historical.
The result is an activity that will eventually produce serious consequences and currently sits outside every mechanism designed to constrain serious consequences.
Hasn’t the doctrine already made this move?
Yes, and recently, which is what makes the silence on harvesting hard to defend as a considered position.
On 7 February 2024, CISA, the NSA, and the FBI, joined by the Department of Energy, EPA, TSA, and the cyber agencies of Australia, Canada, the UK, and New Zealand, published advisory AA24-038A on PRC state-sponsored activity against US critical infrastructure. The central assessment was not that the activity was espionage:
“Volt Typhoon’s choice of targets and pattern of behavior is not consistent with traditional cyber espionage or intelligence gathering operations, and the U.S. authoring agencies assess with high confidence that Volt Typhoon actors are pre-positioning themselves on IT networks to enable the disruption of OT functions across multiple critical infrastructure sectors.”
Three details in that advisory matter more than the headline.
Nothing was stolen. The agencies recorded that the actors “exhibit minimal activity within the compromised environment,” and that industry reporting showing they “do not exfiltrate data” was “consistent with the U.S. authoring agencies’ observations.” The activity was judged serious in the absence of theft.
The judgment rested on future purpose. The agencies assessed that Volt Typhoon “primarily collects information that would facilitate follow-on actions with physical impacts.” The act was characterized by what it would enable, not by what it did.
The timescale was years. The agencies “observed indications of Volt Typhoon actors maintaining access and footholds within some victim IT environments for at least five years,” with one victim having credentials extracted twice across 9 months and another across a 4-year period.
Source: CISA, NSA, FBI and partners, “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure,” advisory AA24-038A, 7 February 2024, cisa.gov.
So the analytical apparatus exists. Governments have demonstrated they can classify a silent, non-damaging, long-duration collection activity as something categorically beyond espionage, on the basis of what it sets up. They built that reasoning and then applied it to exactly one case.
How is harvesting structurally the same?
Both are collection whose meaning lies entirely in a later act. The difference is which half is missing at the time of collection.
| Pre-positioning in critical infrastructure | Harvesting encrypted traffic | |
|---|---|---|
| Damage at the time of the act | None | None |
| Detectable by the target | Rarely, and only through dedicated hunting | Never |
| Data taken | None, in the assessed cases | Everything, in unreadable form |
| What is missing at collection time | The decision to act | The capability to read |
| Duration observed | At least 5 years of maintained access | Indefinite; storage is the only limit |
| Basis for judging it | What it would enable later | What it would enable later |
| Named in doctrine | Yes, since February 2024 | No |
The last two rows are the argument. Both activities are judged, if they’re judged at all, by a future they make possible. Only one has been named.
The reversal in the middle row is worth sitting with. Pre-positioning withholds the act and holds the capability. Harvesting performs the act and waits on the capability. If anything, the second is the more committed posture, because the collection has already happened and cannot be recalled, whereas an implanted foothold can be abandoned.
What does the strongest counterargument say?
That collection is the one thing states have always agreed to tolerate, and that eroding it would cost more than it saves.
The serious version runs like this. Signals intelligence is the oldest and most stable form of state competition, it’s practiced by every capable state including every state that would have to agree to a new norm, and it functions as a stabilizer rather than an escalation, because states that can see each other misjudge each other less. Recording ciphertext is the least intrusive form of it available, touching nothing the target owns and leaving the target’s systems exactly as they were. Declaring it an act of cyber conflict would criminalize the baseline behavior of every intelligence service on earth, produce a norm nobody intends to honor, and weaken the norms that do constrain genuinely destructive activity by association.
There’s also a practical objection. A norm that cannot be verified or attributed is a norm that punishes only the honest. Nobody can detect harvesting, so a prohibition would bind the states that comply and free-ride the states that don’t.
Most of that holds, and it defeats a claim I’m not making. I’m not arguing harvesting should be prohibited, and a prohibition would indeed be unverifiable and unobserved.
What it does not answer is the naming problem. Volt Typhoon was not prohibited either. The advisory created no rule and imposed no penalty. What it did was give the activity a name, distinguish it from espionage in public, and assert a shared understanding among 10 government agencies across 5 countries about what the behavior was for. That’s a doctrinal act with real effects: it shapes what gets briefed, what counts as an indicator, what a response can be justified against, and what a state can be told to stop doing without a treaty existing.
Harvesting has received none of that, and the objection that a prohibition would fail says nothing about whether an articulation is worth having.
Where does this argument stop holding?
Four boundaries.
- This is a doctrinal claim, not a legal one. Nothing here asserts harvesting violates international law. It probably doesn’t, and that’s the point being made rather than the point being disputed.
- The pre-positioning parallel is an analogy, and analogies have limits. Volt Typhoon involved unauthorized access to victim systems. Passive collection off a wire involves none, and that difference is legally significant even where the structure of the reasoning is shared.
- “Act of cyber conflict” is a contested term with no agreed definition, which cuts both ways: it’s available to be applied here, and it carries less weight than it sounds like it should.
- The argument depends on decryption eventually arriving. If a cryptographically relevant quantum computer never gets built, harvesting stays exactly what it appears to be today, which is a very large archive of noise.
Common misconceptions
- “Harvesting is illegal.” No general rule of international law prohibits peacetime intelligence collection, and no cyber norm reaches an activity that causes no damage.
- “It’s an attack.” Under every current formulation it fails the threshold, because nothing is damaged, impaired, or accessed. That’s the gap this note is about.
- “Calling it an act of cyber conflict means calling it an act of war.” It doesn’t. The Volt Typhoon advisory named an activity as beyond espionage without asserting armed attack or triggering any legal threshold.
- “Nobody has ever classified silent collection as serious.” They have, in February 2024, for pre-positioning, on the basis of deferred purpose and with no data taken.
- “A norm would fix it.” A norm nobody can verify would mostly bind the compliant. The gap worth closing is articulation rather than prohibition.
Questions people ask
Is harvesting encrypted data against international law? No general rule prohibits peacetime intelligence collection, and the cyber norms address damage rather than recording, so the activity sits outside both. That absence is what the argument is about.
What would it change to call it an act of cyber conflict? Naming does work even without prohibition. The Volt Typhoon advisory imposed no penalty and still established a shared public characterization across 10 agencies in 5 countries, which shapes briefings, indicators, and what a state can be asked to stop.
How is this different from ordinary espionage? Ordinary espionage requires capability at the moment of the act. Harvesting separates the act from the capability by years, so the collector builds an archive before knowing whether it will ever be readable.
Why does the Volt Typhoon comparison matter? Because it’s the precedent. Agencies classified a silent, non-damaging, multi-year collection activity as beyond espionage based on what it would enable later, and did so in a case where nothing was exfiltrated at all.
Could a state be held responsible for harvesting? Not under any existing mechanism. Attribution requires detection, detection is impossible for passive collection, and the harm surfaces years after the act.
Does this mean my organization should treat it as an attack? The note argues about how states and doctrine should characterize the activity, and it stops there. What any specific organization does about its own exposure is a different question with a different answer.
Is anyone working on this? SIPRI’s 2025 survey found “a lack of dedicated institutions that focus on assessing quantum’s impact on peace and security,” and that existing initiatives “rarely address arms control, deterrence or dual-use risks.” The related distributional problem is in The Quantum Capability Asymmetry.
If it can’t be verified, why name it? Because naming and prohibiting are different instruments. Verification constrains what a prohibition can achieve, and it has no bearing on whether a shared characterization is useful, which the pre-positioning case demonstrates.
The map is free and I keep it that way. When this question stops being doctrinal and becomes a specific institution’s exposure to a specific adversary, that’s the work I do at LaMarr Labs.
Go deeper
- Harvest Now, Decrypt Later (HNDL) for the underlying threat model
- Store-Now-Decrypt-Later Actor Landscape for who is plausibly collecting
- The Quantum Capability Asymmetry for the distributional half of the same problem
- The No-Warning Problem for why none of this announces itself
- The Coalition Interoperability Gap for the other place national policy fails to converge
Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.