HomeRapidalertDokos & Deepfake: How the attack on Maximou took place and what were the...

Dokos & Deepfake: How the attack on Maximou took place and what are the countermeasures

“I thought I was talking to Umerov. It was live, I saw him, just like I see you now.” The statement by Secretary General of National Security Thanos Dokos is the first official public confirmation from a high-ranking official of a NATO member state that real-time AI deepfakes have already surpassed the security protocols we have — and that this happened here, now, in Greece. The Dokos deepfake attack is not an isolated incident but operational evidence of a new era of hybrid threats.

Deepfake attack on Dokos - Cyberattack warning signal in Parliament
The Dokos deepfake attack was the first official confirmation of real-time AI social engineering on a high-ranking NATO official.

The Maximos Mansion described the incident as a “hybrid attack using highly advanced Artificial Intelligence technology.” True — but imperfect. Because the technology used is not exotic or inaccessible; it is freely available on GitHub and runs on gaming GPUs that you buy at any online store. That is the true scale of the problem.

The debate about whether Dokos should resign, whether Maximou is to blame, or whether the opposition is exploiting the situation is noise. The real question is not political — it is technical and institutional: how was the attack possible, why was it not detected, and what countermeasures are in place. These are covered in this investigation.

See also: Deepfake scams: When you can't even trust the voice you hear

How the Dokos deepfake end-to-end attack worked

Russian business “pranksters” Vovan (Vladimir Kuznetsov) and Lexus (Alexei Stolyarov) arranged a video call with the Greek Secretary General of National Security, posing as Ukrainian Defense Minister Rustem Umerov. Dokos saw on his screen what he thought was a live connection with Umerov: he was moving his lips, reacting to what was said, expressing small reactions. None of this was real.

The execution of such a real-time deepfake attack is broken down into three steps. First, material collection (1-2 hours): the attacker needs public audio and video of the target. For a Minister of Defense, there are hours of material available on YouTube, news sites, and interview archives. All it takes is 5-30 seconds of clean audio for voice cloning and 200-500 frames of video for a face model.

Second, training (2-4 hours): fine-tuning a pre-trained TTS model (XTTS-v2, Fish Speech or RVC) for real-time voice conversion with latency below 100ms, and training InsightFace inswapper or FaceFusion for real-time face swap at 25-30 fps.

Third, execution: the attacker's voice goes through voice conversion and comes out as Umerov's voice in applications that support virtual audio, the camera image goes through face swap and comes out as Umerov's face in a virtual camera. Zoom, Teams or a browser-based platform that supports virtual outputs.

Pipeline of Dokos deepfake attack - Collection Training Execution in 5 hours at a cost of 5 euros
The three-stage pipeline of the Dokos deepfake attack: material collection, training, real-time execution — total cost 2-5€ on cloud GPU.
Vovan Lexus deepfake pipeline - face swap and voice cloning setup
Typical workshop for real-time deepfake video call — voice cloning with XTTS-v2/RVC and face swap with InsightFace/FaceFusion.

The really worrying thing is the cost: RTX 3080 used for 500 euros, open source software for free, or cloud GPU on Vast.ai / RunPod for 2-5 euros for the entire attack. Five euros for an attack on the state security of a NATO member country.

Why was the deepfake not detected during the call?

Dokos was not “fooled” because he was naive or careless. He was fooled because the verification systems at his disposal were not designed to deal with this threat. Three factors contributed to the  deepfake attack on Thanos Dokos passing.

Confirmation bias played the first role: Dokos had already met Umerov in person recently, there were open topics, and his brain saw what it expected to see. Second, the synthetic microexpressions of modern face-swap models produce in real time nods, blinks, small head movements based on the audio context — “Umerov” reacted precisely because the model was designed for this.

Third, video compression acted as an accomplice. In a typical video call (720p or 1080p, H.264, 2-4 Mbps) even real faces appear with compression artifacts. Deepfake artifacts get lost in this “noise.” A deepfake in raw 4K is much easier to detect than a deepfake in a compressed video call stream.

See also: INTERPOL: Phishing, Ransomware and AI Scams Sweep Asia-Pacific

Vovan & Lexus: a tool of hybrid warfare, not a "prankster"

Let’s stop calling them “pranksters.” Vovan & Lexus are an operational duo operating as part of the Russian information machine — documented, systematic, with strategic goals. Their track record since 2020 includes Boris Johnson (2020, believed to be talking to Zelensky), Roberta Metsola (2022, President of the European Parliament), multiple Foreign Ministers from France, Germany, Spain, and Poland, and now Thanos Dokos.

The evolution of the tactic is clear: from audio-only phishing (2012-2020), to basic video (2020-2022), to full AI real-time deepfake synthesis (2023-present). Every year the technology becomes more accessible and more convincing. The goal is not always to gather information; it is equally — perhaps primarily — to create political damage. The videos are strategically distributed to Russian media, Telegram channels, and anti-NATO platforms to “prove” the incompetence of Western leaderships. The opposition demanding Doku’s resignation is providing exactly what they wanted: internal turmoil.

Real-time deepfake AI attack - Dokos and video call scandal
Vovan & Lexus have been using AI deepfake in business calls since at least 2023, with documented targets in 5+ European leaderships.

Level 1 Countermeasures against Dokos deepfake: procedural, free, effective

There is no single way to protect, but there is a combination of measures that makes such attacks extremely difficult. The simplest and most effective: callback rule. No call with high-profile participants starts as an incoming call. You get a callback request from “Umerov”? You don’t answer. You hang up. You call back to the number you’ve already verified — the Defense Ministry office in Kiev, an embassy attaché you know, or the back-channel via diplomatic mail. The attacker doesn’t control this channel; the attack ends there.

Second measure: out-of-band shared secret. During each in-person meeting, a recurring keyword is defined that changes every week. At the beginning of each video call, it is requested. A stronger variant is the TOTP verbal challenge: shared Authenticator app (Google Authenticator/Duo or Authy), the interlocutor says the 6-digit code he sees at that moment, valid for 30 seconds. It cannot be forged by an attacker who does not have access to the shared secret.

Third, liveness tests within the call. Real-time face-swap models have specific weaknesses that you exploit on the spot: head rotation test — “turn left, let me see you in profile”; at an angle >45° 3D warping artifacts visible to the naked eye appear, the face “breaks” or produces ghosting. Hand occlusion — “put your hand in front of half your face”; models do not properly handle the covering of part of the face by objects. Sudden lighting change — turn on a light next to you or momentarily cover the camera; models lose texture consistency in abrupt lighting changes.

Physical prop — “hold up a piece of paper with today’s date written in your hand.” Important caveat: these tests are working now; 2027-2028 models may have already encountered them. So it shouldn’t be your only line of defense.

Deepfake detection real-time - AI synthetic video detection
Real-time deepfake detection tools (Intel FakeCatcher, FaceForensics++, rPPG) work well in lab conditions but accuracy drops in compressed video call streams.

Level 2 Countermeasures against the Dokos deepfake: technical — where Greece lags behind

If the call was made via Zoom, Teams, Google Meet, or any commercial platform, there is a fundamental architectural problem: these platforms verify an account, not the identity of a person or device. The “Umerov_Ministry_Defense” account can be created by anyone. The only answer that is not bypassed by deepfake is cryptographic identity verification that is not based on what you see or hear: mTLS with a hardware security module.

Practically: each senior official receives a hardware security token (YubiKey 5 Series or NATO-grade smart card) with an embedded private key that never leaves the hardware. Before connecting, the system performs a mutual TLS handshake — both sides present certificates signed by their HSMs, the handshake verifies the certificate chain up to the NATO Root CA, and only then does the encrypted session open. Even if someone perfectly steals Umerov’s voice and image, they cannot steal the private key that is in the physical possession of the real one. The handshake fails, the call fails.

Step 1: Each senior official receives a hardware security token (HSM — YubiKey 5 Series or NATO-grade smart card) with an embedded private key that NEVER leaves the hardware. Step 2: Before connecting, the system performs a mutual TLS handshake: Official A (Dokos): → TLS ClientHello → Certificate: [CN=Dokos.T, O=GR-NSC, CA=ΥΥΠ-CA] → Digital Signature with private key from HSM Official B (Ομεροφ): → TLS ServerHello → Certificate: [CN=Umerov.R, O=UA-MOD, CA=UAMOD-CA] → Digital Signature with private key from HSM Step 3: Mutual verification of certificate chain: Umerov cert → UA Ministry of Defense CA → NATO Root CA ✓ Step 4: Only after verification is the encrypted session opened.
mTLS with hardware security module - the countermeasure against the Dokos deepfake attack
mTLS with hardware security module (YubiKey/HSM) is the only countermeasure that is not bypassed by deepfake — the private key never leaves the physical hardware.
Hardware security keys (e.g. YubiKey 5 Series) ensure that only physical possession of the token allows successful authentication.

These systems already exist: NATO SecNet, EU TESTA, Cisco Webex Government (FedRAMP High), classified SVTC systems. The real question that no one has answered is why a Secretary of National Security used a commercial platform to communicate with high-ranking officials.

For the second layer, there are real-time deepfake detection with clear limits: Frequency Domain Analysis detects characteristic artifacts in the Fourier transform of GAN-generated faces with >90% accuracy in raw video, but in compressed video call streams the accuracy drops to 60-70%. rPPG (Remote Photoplethysmography) detects heartbeats from micro-color changes in the skin (a synthesized face has no blood flow), but requires high-quality well-lit video. Intel FakeCatcher, the most reliable commercial detector, has 96% accuracy in lab conditions that do not reflect the real call. Detection tools are useful as a second layer, not as a primary defense.

See also: Fraudsters clone famous person's voice to extort money

Also useful is ASN logging and metadata analysis. The Autonomous System Number reveals which provider the connection is coming from — if the “Ukrainian official” is connecting via a Russian ASN or VPN exit node in Moscow, that’s an immediate red flag. IP geolocation, user agent / client fingerprint, and jitter/latency patterns provide additional signals that can be analyzed automated and in real-time for any call involving high-ranking officials of a country.

3-layer defense against the Dokos deepfake attack - procedural technical organizational
Defense at 3 levels against real-time deepfake: procedural (callback, TOTP), technical (mTLS/HSM), organizational (red-team exercises, incident response protocol).

Timeline of ignored warnings before the Dokos deepfake attack

The deepfake attack on Thanos Dokos was not a bolt from the blue. The exact same tactic had been recorded, documented, and circulated as an advisory for three consecutive years prior to the incident. The timeline of warnings that Greek state security had at its disposal:

March 2023 — ENISA issues advisory on AI-enabled social engineering and voice/video cloning, with precise reporting of risk to senior officials. Public, available to every European CERT.

January 2024 — NATO CCDCOE publishes Hybrid Threats bulletin that names Vovan & Lexus as state-linked operators and describes the exact real-time deepfake video call tactic.

November 2024 — The Boris Johnson incident (2020) was discussed at the European Council-level security briefing after the escalation of the tactic. All member states receive access to the specific documents/frameworks.

Q2 2025 — The attack on Roberta Metsola triggers a European Parliament security review and renewed advisories to all national parliaments.

July 2026 — Dokos. Three years after the first ENISA advisory, a Secretary General of National Security connects to a video call with a foreign official via a commercial platform, without mTLS, without hardware token, without second-officer monitoring, without pre-call back-channel verification. The incident was not unforeseeable. It was predictable and preventable.

Level 3 Countermeasures against Dokos deepfake: where the system collectively failed

Vovan & Lexus have been using AI deepfake in operational calls since at least 2023.This is not unpublished information. NATO CCDCOE, ENISA and every European intelligence agency has issued advisories on this very tactic. The question that should be asked is not “why did Dokos speak” but: why was there no briefing and simulation exercise for high-ranking officials regarding AI deepfake social engineering?

The answer reveals an institutional gap: security organizations inform about threats but do not train the people most at risk to deal with them. The difference between “I know there are deepfakes” and “I have received a simulated deepfake attack” is huge. What needs to be done now: tabletop exercises on a quarterly basis where high-ranking officials “receive” simulated deepfake calls from an internal red team; real-time duty officer who monitors metadata and has the right to say “stop the call” at any time; pre-call verification SOP via back-channel for every call with a high-ranking official of a foreign country.

Incident Response Protocol in five steps

1. Immediately stop any follow-up action based on the compromised call — stop email threads, do not forward requests, hold on decisions made during the call.

2. Preserving evidentiary data: screen recording of the call where possible, metadata dump from the platform (connection logs, IPs, session IDs), timestamps, recording client version and jitter/latency patterns for later forensic analysis.

3. Information to the Hellenic Emergency Management Agency with complete technical data for attribution and possible interconnection with other incidents that have been recorded in Greek bodies.

4. Informing through official channels NATO CCDCOE, ENISA and the actual member involved (in this case the Ukrainian Ministry of Defense) so that they are aware that Umerov's image was used for an attack against an allied state.

5. Controlled disclosure that does not amplify the incident—acknowledgement of the event, technical explanation without acknowledging the Russian information damage operation.

What other countries have already done

While Greece is discovering the threat after the Dokos deepfake attack, other countries — many with smaller GDPs and smaller state apparatuses — have already moved the communication of high-ranking officials to cryptographic identity infrastructure:

Estonia (2022): after a wave of Russian phishing attacks, all top-tier government officials moved to mandatory mTLS with hardware key for all communication with foreign officials. Platform: e-Estonia government cloud, not Zoom/Teams.

Czech Republic (2023): mandatory quarterly deepfake red-team exercises for every member of the government and their chief-of-staff. The exercises are carried out by the National Cyber ​​and Information Security Agency (NÚKIB).

United Kingdom (2024): Cabinet Office banned the use of WhatsApp and Signal for ministerial communications, mandatory equipment of FCDO-issued devices with hardware attestation, mandatory pre-call verification protocol for every foreign call.

NATO CCDCOE (2024): publishes complete SOP for prevention, detection and response to AI-enabled social engineering attacks against state officials. The SOP is available to every allied nation. Greece has never incorporated it into a national protocol.

The cost of countermeasures: why this debate is not about money

The costing of countermeasures is where the government has no excuse. For a full mTLS + hardware token + red-team program covering the top-500 government officials in Greece, the first year cost is:

Hardware tokens (500 × YubiKey 5C NFC bulk pricing): ~€22,500 one-time. Amortized over 5 years: €4,500/year.

PKI infrastructure (hosted Root CA, open-source stack): €150,000-300,000 setup + €50,000/year operations.

Quarterly red-team exercises (external contractor or internal capability): €200,000/year.

First year total: under €500,000. For comparison: the cost of political damage from a single successful deepfake incident (media cycle, external image of the country, internal disruption, potential information leak) exceeds this amount by orders of magnitude. The non-funding of this program is not a budget issue. It is a matter of priorities.

The specific obligations after the deepfake Dokos: who, what, when

After the Dokos deepfake attack, the generalized call to “take action” is the main tool for avoiding responsibility. The measures have specific responsibilities and specific timelines:

The EYP must immediately issue an operational directive to all General Secretaries, Deputy Ministers and Offices of the Prime Minister/Ministers with: (a) mandatory callback protocol for every foreign call, (b) prohibition of the use of commercial video platforms for communication with foreign officials at Minister level and above, (c) mandatory reporting of every suspicious contact.

The Ministry of Digital Governance must announce within 90 days and complete within 180 days the procurement of hardware security tokens and PKI infrastructure for top-500 government officials. The tender is well below the amounts required by an International or European tender.

The competent Committee on Institutions and Transparency of the Parliament must summon the competent Minister to a hearing within 15 days on: (a) why the NATO CCDCOE SOP was not incorporated into the national protocol, (b) who signs the procedure for communication between senior officials and officials abroad, (c) is there a provision for tabletop exercises deepfake attacks.

The National CSIRT and the CERT EDYTE must, within 60 days, issue a public technical advisory (as NATO CCDCOE and ENISA did) with specific IoCs, detection signatures and mitigation checklists that every Greek entity can use.

Deepfake face swap revelation - forensic analysis of synthetic video
Forensic synthetic video analysis: frequency-domain artifacts, rPPG heart-rate detection, and ASN metadata are the main post-incident tools.

The conclusion no one wants to hear

The Dokos deepfake attack is not just about Greece and it is not just about Doko. In every ministry, every organization, every company, video calls are made with people you “see live on screen” and trust because you see them. This assumption has always been slightly fragile. Since 2026, it is inadequate.

Identification must be transferred to three levels: something you have (hardware token that never leaves your hands), something you know (shared secret outside the digital channel) and cryptographic proof (digital signature that mathematically proves who you are). The face now belongs to the category of “something anyone can fake”. Until states, organizations and businesses incorporate this reality into their protocols, Vovan, Lexus and anyone else with a gaming PC and an internet connection will continue to make appointments with anyone they want — and “see them live”.

Frequently Asked Questions: Deepfake attack on Thanos Doko

Q: How did the deepfake attack on Thanos Dokos happen?

Russian operatives Vovan (Vladimir Kuznetsov) and Lexus (Alexei Stolyarov) organized a video call with the Greek Secretary General of National Security posing as Ukrainian Defense Minister Rustem Umerov. They used real-time AI deepfake technology: voice cloning with a fine-tuned TTS model (XTTS-v2 or similar) and live face-swap with InsightFace/FaceFusion on a virtual camera. The meeting app only sees the virtual outputs — there is no way to distinguish the attack with the default tools.

Q: Who are Vovan and Lexus?

Vovan (Vladimir Kuznetsov) and Lexus (Alexei Stolyarov) are a Russian operational duo operating as part of the Russian information machine since 2012. They have targeted Boris Johnson (2020), Roberta Metsola (2022), multiple Foreign Ministers from France/Germany/Spain/Poland, and Thanos Doko (July 2026). Their goal: gathering information and creating political damage to Western leaderships.

Q: How can I recognize a deepfake video call in real time?

Real-time face-swap models have certain weaknesses. Ask for head rotation (turn to profile — 3D warping artifacts appear at angles >45°), hand occlusion (put your hand in front of your face — models don't handle occlusion well), sudden lighting change (turn on a light next to you — models lose texture consistency), and physical prop (hold up a piece of paper with today's date written in your hand). Best practice: callback rule — you call back to a verified number.

Q: What is the cost of preventing deepfake attacks at the state level?

For a comprehensive mTLS + hardware security tokens + red-team exercises program covering the top-500 government officials in Greece, the first year cost is under 500,000 euros: hardware tokens (500 × YubiKey 5C NFC) at ~22,500€, PKI infrastructure at 150-300k€, quarterly red-team at 200k€/year. Much below the political damage cost of a single successful deepfake incident.

Q: What is mTLS and how does it block deepfakes?

Mutual TLS (mTLS) requires both sides of a connection to present cryptographic certificates signed by a hardware security module (HSM) such as a YubiKey. The private key never leaves the physical hardware. Even if someone perfectly steals a target’s voice and image, they can’t sign the TLS challenge without physical possession of the HSM. The handshake fails, the call is not established.

Q: Which countries have already adopted countermeasures against deepfake attacks?

Estonia (2022) has mandatory mTLS with hardware key for all foreign counterpart communications of senior officials, via e-Estonia government cloud. Czech Republic (2023) performs mandatory quarterly deepfake red-team exercises for each member of government, by NÚKIB. United Kingdom (2024) banned WhatsApp/Signal for ministerial communications and requires FCDO-issued devices. NATO CCDCOE has published a comprehensive SOP for prevention/detection/response, available to every allied nation.

What can you do?

Pressure for institutional change does not come spontaneously. It comes when citizens, business executives, and journalists ask specific questions of specific officials.

As a business executive: immediately implement the callback rule in your own organization for every video call that concerns financial transactions, HR decisions or negotiations. If your CFO “calls” you for a wire transfer, hang up and call back to a number you have in your contact list. The same Dokos deepfake that hit the Secretary of National Security also hits private companies daily.

As a reader of SecNews: share this article about the Dokos deepfake attack with every executive, public official or IT-security professional who makes video calls with high-profile individuals. Knowledge of the callback rule and the TOTP challenge has prevented attacks worth millions of euros on private companies. No legislation needed — information needed.

See also: Deepfake scams: How not to trust even the voice you hear

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS