Article
When No Ransom Note Arrives: Quiet Breaches may be an Early Warning for Post-Quantum Risk

Why data theft with no extortion attached deserves closer attention from financial services, banking, pharmaceutical and healthcare IT leaders, and what can be done about it today.
A breach with no ransom note
In late January 2026, an intruder used stolen credentials belonging to a French civil servant to access FICOBA, the national registry that indexes every bank account opened in France. Over sixteen days, before the access was detected and shut down, the attacker viewed records tied to roughly 1.2 million accounts: IBANs, account holder names, addresses and, in some cases, tax identification numbers. Officials were clear that account balances and transaction data were never exposed.
No ransom demand followed. No leak site listing appeared. The data was simply, quietly, taken.
That absence of a ransom note is worth pausing on. Two years of breach reporting has trained IT leaders to expect a fairly predictable sequence: intrusion, encryption or exfiltration, then extortion. When the final step doesn’t happen, it is tempting to read the incident as a near miss, contained before any real damage was done. But a theft with no obvious monetisation attached should also prompt a different question: “What if the value of the data was never in selling it back, but in holding on to it?”
A pattern worth reading correctly
We are not suggesting the FICOBA breach has been formally attributed to a Harvest-Now, Decrypt-Later (HNDL) operation. No such attribution has been made, and the identity of the attacker has not been disclosed. But the shape of the incident, quiet credential-based access, selective exfiltration of long-lived personal and financial identifiers, no ransom and no leak, is consistent with the profile security researchers have been describing for HNDL activity for several years now:
Adversaries who capture sensitive data today on the expectation that quantum computing will eventually make it readable, and who are willing to wait years for that value to mature.
This is precisely why financial services, banking, pharmaceutical and healthcare organisations sit at the top of the target list. A transaction history, a genomic dataset, a clinical trial record or a set of banking credentials does not lose its value the way a one-off password does. Recent research has also narrowed the timeline that matters here. Several papers published between May 2025 and March 2026 reduced the estimated number of qubits needed to break RSA-2048 encryption from around twenty million to under one million, and as low as 100,000 in some proposed architectures. The point is not that a cryptographically relevant quantum computer exists today. It is that data copied now may still be sensitive on the day one does.
Why some sectors carry more of this risk
- Financial services and banking: Account data, transaction histories and regulatory filings retain value for years, and a stolen dataset can be repurposed for fraud, fraudulent direct debits or identity theft long after the original theft.
- Pharmaceutical and life sciences: Clinical trial data, drug formulation research and regulatory submissions often carry commercial value for a decade or more.
- Healthcare: Patient records, genomic data and treatment histories carry confidentiality obligations that do not expire when the record does.
- Legal, government and critical infrastructure: Correspondence, negotiations and configuration data can retain intelligence value long after the point of theft.
Closing the gap: An audit, then the right combination of controls
Two things follow from this. First, organisations need a clear view of where they are exposed today, not just to current attack techniques, but to the retrospective decryption of anything already in an adversary’s hands. Second, migrating to NIST’s finalised post-quantum algorithms is necessary, but on its own it is not sufficient.
This is the gap our partner Quantropi’s guidance addresses directly. Even where PQC algorithms are correctly implemented, the key exchange itself is very often still negotiated in-band, over the same channel as the data it is meant to protect, whether via IKEv2, MACSec key agreement or a standard TLS handshake. That means the exchange itself can still be intercepted and stored today, ready for decryption later. Quantropi’s Digital Quantum Key Distribution (D-QKD), delivered through the QiSpace platform, addresses this by delivering keys out-of-band and in software, without dedicated optical fibre or specialist endpoint hardware, so there is no in-band key exchange left for an adversary to capture.
For systems that cannot be upgraded at all, legacy platforms, older network hardware, or appliances at end of vendor support, Quantropi’s Proxy-Q approach places a quantum-safe perimeter in front of them, extending protection without requiring the underlying system to change.
Where Covenco adds value is in the step before any of that: understanding, in practical terms, where an individual organisation’s exposure actually sits. Our engineers work across servers, storage and networking, and that breadth matters here, because HNDL exposure is rarely confined to a single layer. A quantum-safe audit maps where data of long-term value is created, transmitted and stored, where key exchange is happening in-band, and where legacy infrastructure cannot be upgraded and needs a different form of protection. From there, we work alongside Quantropi to put the right combination of D-QKD, Proxy-Q and PQC migration in place, without asking you to replace infrastructure that still has years of useful life left in it.
The hardware layer is quietly catching up too
Quantum-safe capability is no longer confined to overlay solutions bolted onto existing infrastructure. It is starting to arrive built into the hardware itself, and this is an area where our IBM Gold Business Partner status and long-standing IBM Power and IBM FlashSystem Storage experience puts us in a strong position to help.
IBM Power11, the latest generation of the Power server platform, includes NIST-approved quantum-safe cryptography built into the hardware, designed specifically to help protect against harvest-now, decrypt-later attacks as well as firmware integrity attacks. On the storage side, the fifth-generation FlashCore Modules in the current IBM FlashSystem range embed quantum-safe encryption directly at the module level, alongside the ransomware detection and immutable snapshot capabilities that are now standard across the family.
For organisations still running Power9 or earlier Power systems, or older-generation FlashSystem storage, an upgrade path to current hardware brings quantum-safe protection in as a baseline capability, rather than a separate project.
This is not a coincidence of IBM’s product roadmap. IBM Research in Zurich developed two of the algorithms selected in NIST’s finalised post-quantum cryptography standard, and a third was co-developed by a scientist now at IBM Research. IBM has also been one of the most consistent investors in quantum computing hardware over the past decade. That combination, quantum research pedigree feeding directly into the cryptography embedded in enterprise hardware, is a reasonable basis for confidence that IBM’s approach to quantum-safe infrastructure will keep pace with the threat, rather than needing to be retrofitted again in a few years.
For customers weighing up a Power9 or early Power10 refresh, or a FlashSystem upgrade already under consideration for performance or capacity reasons, quantum-safe encryption is a material factor worth adding to that business case, not just a security team’s concern.
Where to start
None of this requires a wholesale infrastructure replacement, or an immediate answer to exactly when a cryptographically relevant quantum computer will exist. It requires an honest audit of where long-lived, sensitive data sits today, in transit and at rest, and a realistic plan for closing the gap in the order that matches your actual risk.
We have published two guides from Quantropi in our resource library that go into the detail behind this: Digital Quantum Key Distribution: Closing the Gap That PQC Alone Can’t Close covers the in-band key exchange problem in depth, and Proxy-Q: A Quantum-Safe Perimeter for Systems You Can’t Upgrade sets out how legacy infrastructure can be protected without replacement.
If you would like Covenco’s independent view on where your organisation sits, or want to talk through a quantum-safe audit alongside a Power11 or FlashSystem upgrade conversation you may already be having, our team is happy to help.