On October 17, 2023, the heads of the five intelligence services that make up the Five Eyes alliance sat on a stage at Stanford University and took questions together in public for the first time. The audience was founders, venture investors, and university researchers, not the defense industry crowd such a panel would once have drawn. FBI Director Christopher Wray, one of the five on that stage, had put a part of the problem in plain numbers three years earlier at the Hudson Institute: roughly 2,000 active FBI investigations tied to Chinese government attempts to acquire American technology and information. The Bureau maintains a public account of that threat.
MI5 Director General Ken McCallum has made the point that matters most for this audience. The collection effort no longer stops at defense contractors and government labs. It reaches promising startups, academic groups, and people who do not think national security has anything to do with them. Quantum computing, quantum sensing, and post-quantum cryptography sit on the priority lists of every service in that alliance, and on the priority lists of the services those five are watching.
Most organizations doing quantum work are not built to absorb that attention. A seed-stage hardware company is a small team, a shared Slack workspace, a university cleanroom booking, and a founder who last thought about security when a laptop was stolen. This article sets out what the public record actually establishes, how collection presents itself inside ordinary working life, and what a program lead can put in place without turning an open lab into a closed one.
Why Quantum Work Attracts Collection
Three things make quantum research worth the cost of collecting against it.
The first is that the output has a long shelf life. A cryptanalytically relevant quantum computer would break the public-key cryptography protecting banking, government communications, and medical records. That machine does not exist yet, which is exactly why encrypted traffic is being intercepted and stored today against the day it can be read. The practice has a name in the security field: harvest now, decrypt later. Anything a team learns about the resource requirements for that machine, or about how the replacement algorithms behave in real systems, keeps its value for decades. The United States National Institute of Standards and Technology (NIST) published the first three replacement standards in August 2024 as ML-KEM, ML-DSA, and SLH-DSA, and the migration methodology at pqcframework.org sets out what moving to them involves. Quantum sensing has a shorter fuse and a more direct military reading. Navigation that works without satellite signals, and magnetometry sensitive enough to detect a submerged hull, are capabilities that governments will pay a great deal to shortcut.
The second is arithmetic. Building a dilution refrigerator supply chain, a fabrication process, and a calibration methodology takes a decade and hundreds of millions of dollars. Copying one takes a hard drive. The 2017 update to the IP Commission Report, issued by the Commission on the Theft of American Intellectual Property, estimated the cost of intellectual property theft to the United States economy at between $225 billion and $600 billion a year, across all sectors. States that have declared quantum a sovereign capability, and cannot close the gap on their own timeline, have an obvious cheaper path. Technology sovereignty is the stated goal on both sides of this: one side is trying to hold a lead, the other is trying to erase it, and collection is the instrument that costs least.
The third is that quantum organizations are unusually soft. They are small, internationally staffed by design, culturally committed to publication, often embedded in universities whose networks are collected in bulk, and rarely old enough to have hired anyone whose job is security. They are also increasingly export-controlled without always knowing it. Quantum computing items came under new United States export controls in September 2024, with allied jurisdictions moving in the same direction, and a great deal of quantum hardware is dual-use, meaning it has both civilian and military applications and is regulated on that basis. Being controlled makes a company a procurement target, which is a different threat from being an intellectual property target and needs a different control.
There is a fourth factor that gets less attention. In a field this young, nobody can reliably say which result is the sensitive one. A calibration trick that looks like housekeeping may be the difference between a device that works and a device that does not. Researchers cannot protect what they have not identified, and identifying it is a judgment call that no policy document makes for them.
What the Public Record Shows
The cases below are drawn from indictments, court records, and official disclosures. They are grouped by mechanism rather than by country, because the mechanism is what an organization can actually defend against.
Talent Programs and Undisclosed Funding
In January 2020, Charles Lieber, then chair of Harvard’s chemistry department, was arrested and charged with making false statements about his relationship with China’s Thousand Talents Plan. According to the Department of Justice, Wuhan University of Technology paid him up to $50,000 a month, about $158,000 in living expenses, and more than $1.5 million to establish a laboratory in Wuhan, while he held United States federal research grants that required disclosure of foreign support. He was convicted in December 2021.
Lieber’s field was nanoscience, not quantum computing, and the charges were about disclosure rather than theft. That is precisely why the case belongs here. The mechanism is a parallel appointment that the home institution never sees, with a contract that assigns rights to research the home institution funded. The November 2019 Senate Permanent Subcommittee on Investigations report on foreign talent recruitment plans documented the same structure across dozens of cases. No hacking is involved. The exposure is contractual, and it surfaces in conflict-of-interest paperwork that most startups do not ask for and most universities process without reading.
Cover Identities
Some services invest a decade in a single person. An officer is given a manufactured nationality, a genuine education, and a career that stands up to a reference check, then placed somewhere useful. The trade calls them illegals: officers operating without diplomatic cover or protection.
Sergey Cherkasov, an officer of Russia’s GRU (Main Intelligence Directorate), spent years as Victor Muller Ferreira, a Brazilian national with a degree from Trinity College Dublin and a master’s from Johns Hopkins. In April 2022 he flew to the Netherlands to take up an internship at the International Criminal Court, was identified by Dutch intelligence at the border, refused entry, and sent back to Brazil, where he was convicted of document fraud. Mikhail Mikushin, also a GRU officer, lived as José Assis Giammaria, a Brazilian researcher, and held a research position at UiT The Arctic University of Norway until his arrest in October 2022.
The same objective is now pursued far more cheaply. In July 2024 the security awareness company KnowBe4 published its own account of hiring a remote software engineer who turned out to be a North Korean operative using a stolen United States identity and an edited photograph. The workstation shipped to the new hire began attempting to load malware almost immediately, and the company’s detection tooling caught it within half an hour. Similar schemes have since produced United States prosecutions of the domestic facilitators who host the laptops. A cover identity that once took ten years to build now takes a résumé, a video call, and an accomplice with a spare bedroom.
Campus approaches sit between those two extremes. The Stanford Review reported that a person using the name Charles Chen spent years contacting Stanford learners working on sensitive research topics, offering one of them a funded trip to Beijing and pushing the conversation onto a monitored messaging platform. No prosecution has followed, and the affiliation remains an allegation rather than a finding. What the account illustrates is the economics: an approach costs nothing, and one acceptance in a hundred pays for the campaign.
Procurement Networks
In October 2022 the Department of Justice unsealed charges against a network built around two Moscow companies, Serniya Engineering and Sertal LLC, which prosecutors described as operating under the direction of Russian intelligence to acquire advanced electronics and testing equipment controlled for export. Vadim Konoshchenok, alleged to be an officer of Russia’s FSB (Federal Security Service), was arrested in Estonia and extradited. In 2023, Nikolaos Bogonikolos, a Greek businessman whose company held contracts with NATO member governments, was arrested in France and accused of sourcing for the same network, with quantum cryptography hardware among the items named.
This is the threat model most quantum companies have never considered. The target is the bill of materials rather than the intellectual property: dilution refrigerators, cryogenic amplifiers, single-photon detectors, arbitrary waveform generators, specialist lasers. A quantum hardware company is both a buyer of controlled goods and, once it has revenue, a seller of them. Its resellers, distributors, and second-hand equipment buyers are part of its attack surface. The United States response has been enforcement-shaped, through Entity List designations, which bar United States suppliers from shipping to named organizations without a license, and through the Disruptive Technology Strike Force launched in February 2023. Enforcement lands on the exporter who did not ask enough questions.
Bulk Cyber Collection
In March 2018 the Department of Justice indicted nine Iranian nationals connected to the Mabna Institute for a campaign against 144 United States universities and 176 foreign universities in 21 countries. Prosecutors put the volume at roughly 31.5 terabytes of academic data, obtained by spear-phishing more than 100,000 professor accounts, of which around 8,000 were compromised. Nothing about that operation was selective. It took what was reachable.
Dutch military intelligence disclosed in February 2024 that a Chinese state actor had placed custom malware on a Ministry of Defence network, and said the same actor had gone after edge security devices well beyond that one network. A quantum research group inside a university inherits the university’s perimeter, its patching schedule, and its incident response capacity, whether or not anyone told the principal investigator.
What the Record Does Not Show
No public prosecution has yet named a quantum computing company as the victim of a completed theft of its core technology. We should say that plainly rather than imply otherwise.
There are two ways to read the gap. One is that the sector is not really a target and the warnings are inflated. The other is that public cases lag the conduct by years, that most victims never learn they were collected against, and that the ones who find out have every commercial reason to stay quiet. Lieber’s undisclosed arrangement ran for years before charges. The Dutch intrusion was found long after it began. Data theft leaves the original in place, so absence of evidence in this domain is close to worthless as evidence of absence. The honest position is that the mechanisms are documented, the official warnings are specific, and the case ledger for this particular sector is still being written.
How Collection Presents Itself
An account published on PostQuantum.com describes three days in Vienna during meetings with a European quantum hardware startup and an investor. The same man appeared on an almost empty train, then at the station an hour later, then at the next table during dinner in different clothes and glasses, then at the hotel bar. At the bar he opened a conversation and steered it repeatedly toward quantum sensing. The author, introducing himself as an agricultural machinery salesman, talked at length about vintage tractors until the man gave up.
Two details are worth keeping. The target was an advisory firm that does not fabricate anything, which tells you how wide the net is. And the conversation, not the surveillance, was the operational part of the encounter.
Elicitation
Elicitation is the extraction of information through conversation that never feels like questioning. It is the highest-volume tactic in this field because it is cheap, legal in most settings, and leaves the target feeling good about the exchange.
Five techniques cover most of it. Flattery invites you to perform: you are the only person who could explain error correction to someone like me. Feigned ignorance puts you in teaching mode, where the instinct is to be generous with detail. Quid pro quo offers a small confidence to earn a larger one. A shared complaint invites agreement, and agreement means specifics. Somebody grumbles that their cryostat never reaches its advertised temperature, and the natural reply supplies your model, your achieved temperature, and what you had to change to get there. Bracketing invites correction: the deliberately wrong guess. If someone says your prototype must have cost five million, and you say it was closer to two, they have the number without having asked for it.
The counter is a prepared answer, decided in advance, for the four or five questions your team gets asked most, rather than silence or blanket suspicion at the conference bar. Something you can say warmly and repeat without thinking. People do not overshare because they are careless. They overshare because they were asked something interesting and had nothing rehearsed.
Access Under a Legitimate Pretext
A visiting researcher asks to spend a week with the team and asks excellent questions. A delegation tour pauses in front of the whiteboard. An investor’s technical diligence keeps drifting from performance figures toward fabrication parameters, and then asks for a walk through the full facility.
None of these is inherently hostile, which is what makes the category difficult. Useful signals are cheap to check. Does the visiting researcher have a publication record you can find? Does the fund have a portfolio and prior investors you can call? Does the diligence request ask for information that no investor at this stage would need in order to price a round? A polite refusal costs almost nothing with a genuine counterparty, who has been refused before and expects it.
Devices, Travel, and Physical Access
Branded memory sticks appear in a car park outside the building. A visitor leaves a phone behind in a meeting room. A laptop disappears from a hotel room during a conference and nothing else is touched, which rules out an ordinary thief. Devices are inspected at some borders and returned. Public charging ports can be modified to pull data from a phone.
Sophisticated organizations run technical surveillance countermeasures, meaning physical sweeps for listening and recording devices. Most quantum teams do not need that, and selling it to them would be selling fear. What every team needs is smaller: a clean device for travel to higher-risk destinations, full-disk encryption, devices powered down at borders, no unmanaged removable media on lab machines, and separate rooms for internal work and external meetings.
Pressure
The least discussed tactic is the one that does the most damage to people. A researcher receives a summons to an embassy with no stated reason and finds an intelligence officer waiting. A visa renewal becomes conditional on cooperation. A conversation includes an unnecessarily detailed reference to family at home. China’s National Intelligence Law of 2017 places a legal obligation on citizens and organizations to support and cooperate with state intelligence work when asked, and several other states apply comparable pressure without writing it down. Where a personal secret exists, it can be used, and services have been running that play for a century.
Treating colleagues as suspects on the basis of nationality is both wrong and useless. It is wrong because the overwhelming majority of the people concerned are the intended victims of this pressure, not its agents. It is useless because it guarantees that the person under pressure will tell nobody. The effective response is the opposite. State in advance, in writing, that anyone approached or pressured can come to a named person, that doing so will not affect their employment or immigration support, and that the organization will help them get to the relevant national authority. The alternative is a scientist deciding alone, at midnight, that they have no choice. They do have a choice, and whether they know it depends on what leadership said before it happened.
Open Sources
Open-source intelligence, or OSINT, is the assembly of a picture from information that was published deliberately. A job advertisement seeking an engineer with cryogenic ion-trap experience for aerospace applications reveals a program, a modality, and roughly a stage. A grant abstract names collaborators and timelines. A conference poster carries the data that did not make the paper. A LinkedIn post celebrating a milestone dates it. A press release names the supplier.
No single item is sensitive, and refusing to publish any of them would be worse than the exposure. The realistic control is a review step: one person who looks at outbound public material against the sensitive list before it goes out, and who has the authority to remove a number.
Seven Controls Worth Having Before You Need Them
None of these requires a security department. All of them can be in place within a quarter.
- Decide what is actually sensitive. One page. Not the field, not the paper, but the specific things: the calibration procedure, the fabrication yield data, the error budget model, the customer list, the supplier terms. Name an owner for each. Review it twice a year. Teams that skip this step protect everything a little and nothing well, and they cannot brief anyone on what to refuse.
- Escort and record visitors. Every external visitor signs in, is escorted, and has a route agreed before arrival. Cover or clear what is on the walls. Agree in advance who answers technical questions and where the boundary sits, so nobody has to make that call under social pressure in front of a whiteboard.
- Run a clean travel kit. A loaner laptop and phone with no history and no stored credentials, full-disk encryption, devices powered off at borders, no sensitive calls from hotel rooms, no unattended devices anywhere. If you cannot fund loaners, strip the primary devices before departure and restore afterward.
- Verify people, not paperwork. Contact references through numbers you found yourself, not the ones on the résumé. Check that publications exist and that the person is on them. Ask about outside appointments, outside funding, and outside contracts at hire, in writing, and ask again annually. Fabricated identities usually fail at an independently sourced reference call, not at a background check.
- Finish the cyber basics. Phishing-resistant multi-factor authentication on email, code repositories, and cloud storage. A patching schedule someone owns. Offline backups tested at least once. No unmanaged removable media. One named contact for incidents who answers at two in the morning. This is unglamorous, and it defeats most of what is aimed at you.
- Ask the export-control question before the collaboration, not after. Controls on quantum items are tightening across jurisdictions, and the exposure runs both ways: what you buy and what you sell. Screen end users and resellers. Get a written opinion before a technology transfer, a foreign national’s access to controlled technical data, or an equipment sale into an unfamiliar market. Retroactive compliance is a legal problem, not a paperwork one.
- Build a reporting route that does not punish. This control returns more than the other six combined. Whoever gets approached, phished, followed, or pressured needs somewhere to take it within the hour, from a named person, with no career consequence and no implication that they did something wrong. Say so out loud, more than once. Then rehearse two scenarios with the leadership team: a laptop stolen abroad, and an employee reporting a direct approach. Half an hour each. The value is not the plan, it’s discovering who does not know who to call.
Open Science, Closed Secrets
Chemists used to smoke in laboratories and pipette by mouth. Nobody legislated that away in a single memo. Safety culture was built over decades out of small mandatory habits, until a researcher who skipped goggles looked careless rather than bold, and the habits stopped feeling like an imposition. The field lost nothing scientifically and gained a great deal.
Research security is at the stage lab safety occupied in the 1950s. The habits are known, they are cheap, and they are not yet normal. In ten years a group that lets an unverified visitor wander its facility will look the way mouth-pipetting looks now.
The balance is real and it does matter for how you set policy. Publication, international collaboration, and learner mobility are how quantum science actually advances, and a sector that shut them down to prevent theft would lose more than the theft costs. The workable line runs between theory and implementation. Publish the physics. Present at the conference. Host the visiting researcher. Compartmentalize the things that took two years of failed runs to learn: the process parameters, the yield data, the tooling changes, the commercial terms. Open science, closed secrets. That distinction is one an organization has to draw for itself, in writing, in advance, and it is the reason control one comes first.
Where Training Fits
Generic annual security awareness training teaches employees to spot a fraudulent invoice and a suspicious link. It does not teach a postdoc how a bar conversation gets steered, what an investor’s diligence request should never contain, or what to do about a summons with no stated reason. In this field the vocabulary of the work is itself the pretext. The person asking the sharpest question about your error correction scheme is, most days, exactly who they appear to be. Nobody can tell the difference by instinct, and instinct is what most teams are currently relying on.
What closes the gap is short, specific, and role-shaped. Researchers and engineers need the elicitation techniques by name and a rehearsed answer for the questions they get asked most. Founders and program leads need the visitor, travel, hiring, and export-control decisions as procedures rather than judgment calls. Boards need enough of the threat model to fund the seven controls without being frightened into overreach. Everyone needs to know the reporting route, and to believe using it is safe.
Quantum Academy teaches exactly that material, in the technical idiom of the field rather than in generic corporate compliance language, and for the people who will be in the room when it happens: the elicitation and travel work for researchers and engineers, the visitor, hiring, and export-control procedures for founders and program leads, and the threat model for the board that has to fund them. The current credentials and their syllabuses are listed at quantumacademy.com/. For deeper technical background on the threat side, PostQuantum.com carries the long-form analysis, and organizations building out quantum teams will find the role definitions at QuantumCareers.com a useful companion when they write the security expectations into a job description for the first time.