Encrypting your sensitive data is necessary, but not sufficient. You need to also bind your ciphertexts *to the specific context *in which they are stored.
https://soatok.blog/2023/03/01/database-cryptography-fur-the-rest-of-us/#database-cryptography