Digital Identity Security: Stolen Faces Crack by 2035 (Updated)

Here's a fact that should make you a little uneasy: someone could be copying your encrypted digital identity security data right now, filing it away, and doing absolutely nothing with it — on purpose. Not because they can't read it yet. Because they're waiting for the day they can.
Digital identity security isn't a lock that stays shut forever — it's a countdown, because identity data encrypted today can be copied, stored, and cracked open years later once the math protecting it gets outdated.
Digital identity security depends on how long your encryption is expected to last — not just whether it works today — because attackers can copy encrypted files now and simply wait for computing power to catch up.
This isn't science fiction. It's already got a name — security researchers call it "harvest now, decrypt later" — and according to the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the National Institute of Standards and Technology (NIST), it's happening today, not someday. Think about that for a second. The threat isn't a future quantum computer showing up and instantly breaking the internet. The threat is that your identity data gets scooped up this year, put in a drawer, and read whenever the lock finally gives out.
Why digital identity security depends on more than just "it's encrypted"
Most of us think of encryption (the math that scrambles your data so only the right key can unlock it) like a safe. You lock it, and it stays locked — end of story. That's a completely reasonable thing to believe, because for most of your life, that's basically been true. But encryption isn't a permanent purchase. It's a bet on how hard a math problem is right now. And math problems that are "impossibly hard" today can become "solvable on a Tuesday afternoon" once computing changes enough.
Starts at 01:38 — this story
Watch this story, in under a minute
A new briefing every weekday — three stories, three minutes.
Subscribe on YouTubeThat's exactly what's coming with quantum computers — machines that process information in a fundamentally different way than the laptop on your kitchen counter, which makes certain math problems (the ones current encryption relies on) much faster to crack. NIST didn't wait around to find out. In 2024, it finalized new encryption standards built to resist quantum attacks: ML-KEM for scrambling shared information, and ML-DSA and SLH-DSA for digital signatures (the cryptographic equivalent of a notarized signature proving a document is really from you and hasn't been altered). These are the tools meant to replace the encryption protecting your identity verification systems, your bank login, and the digital identity credentials more countries are rolling out every year.
What does "post quantum digital identity" mean for identity theft and everyday users?
It means the systems that check who you are — your account logins, your government ID databases, the apps that scan your face or fingerprint — are being rebuilt with encryption strong enough to survive computers that don't fully exist yet. It's less about a futuristic machine arriving and more about closing the gap before it does, which matters directly for identity theft prevention, since stolen identity data sitting in a drawer today is exactly what fuels identity fraud tomorrow. This is the core identity theft risk users and application owners should understand: digital identity, digital access, and digital accounts all depend on identity data that outlives the systems built to protect it, which is why digital identity governance and digital access management now treat digital identity theft as a long-horizon problem rather than a one-time breach.
The sealed letter that changes everything about digital identity security
Picture this. You mail a letter today, sealed with a lock design that's currently unbreakable. Someone intercepts it. They can't open it — not yet. So they don't try. They just put it in a drawer. They're patient. They know that lock design is scheduled to be cracked in ten years, because cryptographers already see the weakness coming. So they wait. Ten years later, the lock breaks — publicly, predictably — and they walk over to the drawer and open the letter like it was mailed yesterday. This article is part of a series — start with Texas Age Verification Law 25 States Now Demand Id Checks Po.
That's digital identity data right now. Your encrypted file isn't guarded by a lock that gets weaker gradually. It's guarded by a lock that works perfectly until, suddenly, it doesn't — and the attacker doesn't need to be there the moment it breaks. They just need to have copied the file at some point before it broke. That's the part that trips people up, and honestly, it's a fair thing to miss. Users are used to thinking of hacking as something that happens in real time. This kind of attack happens in two separate moments, years apart: the theft, and the unlocking. The theft is silent. Users would never know it happened, and neither would the person whose digital identities were copied. Multiply that single theft across every digital identity, every digital account, and every application that stores user identity data in the cloud, and the scale of quiet, patient identity theft becomes clearer — cloud identity records are copied once and read whenever the lock finally fails. This article is part of a series — start with Texas Age Verification Law 25 States Now Demand Id Checks Po.
98–100%
of healthcare records encrypted today are estimated to be vulnerable to retroactive decryption under a "harvest now, decrypt later" attack
Source: analysis of 100+ primary sources, published on ResearchGate
Why biometric data breaks the "just change your password" fix — a digital identity security blind spot
Here's where this stops being an abstract encryption problem and turns into something personal. If a password leaks, users change it. Mildly annoying, sure, but it's fixable in about ninety seconds. Biometric data — a person's fingerprint, iris pattern, the shape of a face — doesn't work that way. It's the person. Permanently. Users can't rotate a face like they rotate a password.
That's why identity verification systems built on biometrics carry a heavier version of this risk. As Biometric Update reported, encrypted biometric records copied today and cracked open a decade from now don't just expose old data — they expose a piece of a person that never expires and can never be reissued. Compare that to a stolen credit card number, which the bank just cancels. There's no "cancel my face" button, and no amount of identity governance can undo a leak of data this permanent.
An attacker capturing encrypted biometric data from an ID document today poses a security risk for static biometric data, such as fingerprints and iris patterns — data that cannot be reissued once compromised.
— summarized from research cited in ResearchGate
And this is exactly where facial recognition and biometric identity verification systems intersect with the quantum problem in a way most users never connect. When a company builds a facial-matching system, the actual comparison — mapping a face into a set of measurements and checking those measurements against a stored record — is only half the security story. The other half is what protects that stored record while it just sits there in a database, waiting for the right access request. If the encryption guarding that database is weak against future computing, the matching algorithm's accuracy doesn't matter at all. The vault door was never the problem. The lock on the vault was.
| Old encryption approach | Post-quantum approach | Status |
|---|---|---|
| Assumes math problems stay hard forever | Assumes attackers can wait decades and plans for it | Legacy — unstarted |
| Signature size ~64 bytes (ECDSA) | Signature size ~4 KB (ML-DSA-65) — about 64x larger | Finalized 2024 |
| Vulnerable to retroactive decryption | Designed to resist decryption even after quantum computers arrive | Standardized 2024 |
| Passwords can be reset if stolen | Still true — but biometric identity data cannot be reissued either way | Ongoing risk |
| Migration status: largely unstarted | Migration status: early rollout across national ID, cloud identity, and enterprise systems | Early rollout 2026 |
| Single-cloud identity silos, minimal access management | Cross-cloud identity and access management with identity governance built in | Emerging practice |
That size jump in the table above isn't a footnote — it's the whole engineering headache right now. A signature that used to take 64 bytes now takes roughly 4,000. Multiply that across every login, every certificate, every account verification handshake happening across cloud platforms and applications worldwide, and users start to see why this migration takes years, not weekends. Bigger signatures mean more data traveling over networks and devices, more strain on systems that were never built to carry that weight, and real pressure on companies trying to keep access fast for users while making digital identity credentials quantum-safe. Previously in this series: Digital Identity Security Stolen Faces Crack Open By 2035 Po.
The myth about digital identity security that even smart people believe
Let's name the misconception directly, because it's genuinely reasonable to hold: users assume that if something is encrypted, it's protected until someone cracks the password or steals the key. Encryption feels like a vault — solid, final, done. You lock it, you walk away, you stop worrying. Nobody teaches users to think of encryption as having a shelf life, the way milk does. Why would you? Nothing in daily life prepares users to imagine an attacker who steals something they can't use for ten years and is completely fine with that.
But that's the correction: encryption protects identity data for as long as the underlying math stays unsolved — not forever, and not automatically. The file can be copied the moment it's created, long before anyone finds a flaw in the lock. Decryption doesn't need to happen at the moment of theft. It happens later, at leisure, against a file that's been sitting quietly the whole time, waiting for access. Some researchers put the odds at 50% or higher that core public-key cryptography (the kind protecting most logins and identity verification today) gets meaningfully compromised by the early-to-mid 2030s. More conservative estimates push that toward 2040. Either way, notice something: the identity data at risk is being created right now, in 2026, years before the risk even activates — and identity fraud built on that data could follow just as far behind.
What Users Just Learned About digital identity security and identity fraud risk
- 🧠 Harvest now, decrypt later — attackers copy encrypted identity data today and wait for the math to become breakable, so theft and decryption can happen years apart
- 🔬 Biometric data can't be reset — unlike a password, a fingerprint or face can never be changed if it's ever exposed
- 🔐 NIST's 2024 standards — ML-KEM, ML-DSA, and SLH-DSA are the new quantum-resistant tools replacing older encryption in identity systems
- 💡 The real question to ask — not "is it encrypted," but "how long is that encryption designed to last"
How to judge digital identity security promises without needing a math degree
Users don't need to understand lattice-based cryptography (the specific quantum-resistant math NIST chose) to protect themselves here. Users need one habit: when a company, bank, or government service says data security is handled because everything is "encrypted," ask a follow-up. How long is that encryption expected to hold? Is it one of the newer, quantum-resistant standards, or an older method that's been fine for twenty years and just hasn't been tested against what's coming?
This matters more for some entities' digital identities than others. A throwaway shopping account? Low stakes, honestly. A national digital identity record, a medical record, a biometric passport scan? Those live in rest — meaning stored, unmoving, sitting in a database for years, often in a cloud environment — which is exactly the condition that makes "harvest now, decrypt later" attacks so patient and so effective. Encryption in transit (identity data moving between a phone and a server, sometimes across mobile networks) matters too, but data at rest is the long game attackers are actually playing.
Common use cases where identity access management and digital identity security upgrades matter most
The common use cases getting the most attention right now are national digital identity programs, healthcare record systems, and financial identity verification platforms — anywhere identity attack vectors touch data that stays valuable for decades. According to Biometric Update, vendors including Fobi, WISeKey, and Atsign are already building quantum-resistant infrastructure into digital identity systems, treating this less like a future upgrade and more like overdue maintenance for access management across every connected device, application, and cloud account a user or organization relies on.
This is also where CaraComp's work in facial recognition intersects with the bigger story. When we evaluate how a facial-matching system performs — accuracy, speed, false-match rates — we're only ever looking at one layer of a much bigger stack. The encryption protecting the enrolled face template sitting in a database, and how long that encryption is designed to hold up, matters just as much as whether the matching algorithm itself is any good, and just as much as the access management rules controlling who can query it. A perfectly accurate facial recognition system built on encryption with a ten-year expiration date isn't secure. It's just secure for now. And "for now" is precisely the phrase that should make anyone pause.
What identity management teams should ask their vendors now
Identity management and identity governance teams evaluating vendors should ask a direct question: does this vendor have a published post-quantum migration plan, or is "encrypted" the entire answer? A vendor that treats digital verification, identity federation between partner systems, and device-level access as separate, unrelated checkboxes is more likely to have a gap somewhere. The strongest answers connect identity management practices to a concrete encryption roadmap, not just a compliance checkbox — one that names how digital identity, digital accounts, and digital access across every cloud application are actually protected, not just described.
Digital identity security isn't about whether your data is encrypted today — it's about whether that encryption protects organizations and individuals for as long as the data stays valuable, because a file copied now can sit untouched for years before it's cracked open later. Up next: Digital Identity Security Stolen Faces Crack Open By 2035 Po.
So here's the reframe worth carrying around: encryption was never a wall. It was always a clock. Every digital identity record with a user's name on it — their identity, their face, their fingerprint — has an invisible countdown attached to it the moment it's created, and the countdown started running long before anyone told them it existed. The unsettling part isn't that quantum computers might arrive someday. It's that the identity data they'll eventually unlock is already sitting in a drawer somewhere, sealed, waiting, across countless devices, cloud accounts, and applications most users have long forgotten about.
digital identity security: Frequently Asked Questions
How does encryption secure identity data online if attackers can just wait for it to break?
Encryption still secures identity data online for as long as the underlying math problem stays unsolved — that's real protection, not nothing. Good encryption secures sensitive data online whether that data lives on a device, in an application, or in the cloud. The issue is only for identity data that needs to stay secret for many years. Encryption that's strong today protects it right now, in transit and at rest, but if a copy is stolen and stored, it can eventually be opened once stronger computing arrives, exposing users to identity fraud long after the original theft. That's why sensitive, long-lived identity records need quantum-resistant encryption specifically, not just "any" encryption.
Do ewallets and digital credentials get encrypted the same way bank accounts do?
Generally yes — ewallets encrypt digital credentials and identity information using similar standards to bank accounts and government identity systems, often relying on the same underlying cryptographic protocols; put simply, ewallets encrypt identity information the same way a bank vaults a physical asset. A wallet provider that has published a migration plan is more likely to be preparing a move toward post-quantum standards like ML-KEM and ML-DSA. If users are trusting a wallet with a scanned ID or biometric data on a mobile device or cloud account, it's fair to ask whether that provider has a public timeline for quantum-safe upgrades.
Can a person be recognized from old biometric data even after security upgrades?
Yes — if a person's biometric data was copied before new protections were added, that older copy can still be recognized and matched against them, because upgrading a company's current systems doesn't erase data attackers already stole years earlier. This is exactly why biometric data is treated differently from passwords: the risk from an old breach doesn't disappear just because the access management defending new user accounts, digital identities, and cloud applications got stronger.
What enables strong access management in a post-quantum digital identity system?
Enabling strong access management in a post-quantum world means combining quantum-resistant encryption standards (like NIST's ML-KEM and ML-DSA) with existing practices like multi-factor authentication, or MFA — using a password plus a phone code or fingerprint. MFA reduces the damage if one factor is compromised, while post-quantum encryption protects the stored identity data itself from future decryption across every application, cloud account, and device a user relies on. Neither one alone is enough; digital identity security needs both working together as part of broader identity access management.
Can better digital identity security reduce identity fraud risk long-term?
Yes, upgrading to post-quantum standards can reduce identity fraud risk, but the timeline matters more than users realize. Because "harvest now, decrypt later" attacks are already collecting encrypted identity data today, switching to stronger encryption now protects data created for new users and accounts, including cloud accounts and application logins, from this point forward — but it can't retroactively protect records already copied under older, weaker encryption. That's the uncomfortable trade-off: the sooner organizations upgrade, the smaller that exposed window becomes, and the smaller the identity theft exposure that lingers afterward.
What does identity security posture mean for compliance and identity governance?
Security posture refers to an organization's overall readiness against threats — its encryption choices, access management rules, and identity governance policies for who can view sensitive user accounts and applications across cloud and on-premise identity systems. For compliance purposes, regulators are starting to ask whether organizations have a documented plan for post-quantum migration and identity federation across partner systems, not just current-day encryption. A strong posture today increasingly means proving that identity management systems, digital identities, and application access are built to remain protected years from now, not only in this budget cycle.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
Online Identity Verification: Why a Passed Face Scan Fails
Getting denied for a loan or account after your face scan "passed" feels confusing — but identity checks and credit decisions are two totally separate systems. Here's how to tell which one actually rejected you.
biometricsBiometric Access: 250 Florida Agencies, One Contractor
Florida just handed a private contractor the keys to its entire fingerprint and face-matching system. Here's what a "biometric back office" actually does — and the four questions you should ask any agency that scans your face or fingerprint.
digital-forensicsWhat Is Digital Identity Verification: 3 Checks, Not One
A digital credential can be flawless and still fail you — because being valid and being trustworthy are two completely different things. Here's the three-part check most "verified" badges skip.
