- The farce surrounding the Dokos case has exposed the recklessness with which obvious security matters are being handled.
- The unforgivable mistakes of the Prime Minister’s National Security Adviser.
- A cybersecurity and artificial intelligence expert dismantles the narrative of an “attack using artificial intelligence.”
- What the processing of the video of Doko’s conversation with the two Russian pranksters reveals.
- The passwords used by the Russian pranksters are still active.
By Paris Karvounopoulos
Thanos Dokos was appointed National Security Adviser by the Prime Minister after his predecessor, retired Vice Admiral Alexandros Diakopoulos, spoke out about the “cruises” made by the Turkish vessel Oruc Reis in waters of Greek interest, which was an uncomfortable truth for the government. But did Mr Dokos have any relevant experience? His time at ELIAMEP, where he became known for the institute’s often controversial stance on Greek-Turkish relations, offered no such assurance.
Unexpected events always expose our vulnerability. For Mr Dokos, it was the two Russian hoaxers, who had previously targeted another New Democracy party figure, Theodoros Roussopoulos. Although the government suffered a setback, it failed to learn the lesson, and the Russians’ second “operation” proved far more damaging.
How did they find Mr Dokos and get in touch with him? Logically, establishing a point of contact with a National Security Adviser should be difficult. However, as cyber security and artificial intelligence expert Federico Carrasco explains, it is ultimately not that difficult. He himself tried to locate Mr Thanos Dokos after the uproar caused by the Russians, and says he had no difficulty doing so.
Since the Russians had no difficulty contacting Mr Dokos, they proceeded with their “hoax operation”. As it turns out, this was not difficult either. The “technical fingerprints” of this incident are significant and worth examining with the help of experts, who noticed all the important details and were alarmed by just how “open” we are at the highest levels.
In early July 2026, it emerged that the Prime Minister’s National Security Adviser, Thanos Dokos, had fallen victim to the Russian hoaxers Vovan and Lexus. They presented themselves as Ukrainian officials and spoke with Mr Dokos via video conference. Speaking on SKAI’s main evening news bulletin, Mr Dokos claimed that he could see his Ukrainian counterpart, Rustem Umerov, live on screen, “just as I can see you”, and that all the official-looking credentials had been provided in advance, including names, addresses and letterheads. He added that the person in the video was a deepfake, created using highly advanced artificial intelligence. The government described the incident as a hybrid attack using AI, stressing that no classified information had been leaked.
Had Mr Dokos in fact followed all the prescribed security measures, and what exactly are those measures?
The hoaxers themselves stated that they simply sent an email to the Prime Minister’s general office from a Gmail account, received a reply about a week later, and then arranged a video call, all without using any sophisticated tools or intruding on any codes. They even sarcastically commented that if some people think a little cosmetic touch-up is a covert special operation, they are free to believe that.
However, between the two narratives, “deepfake using advanced artificial intelligence” and “a simple Gmail account”, there is a technical detail that leaves no room for interpretation. It is this detail that constitutes the truly disturbing aspect of the case.
The password that gives everything away
The video broadcast by MEGA revealed more than just the conversation. It also showed the invitation email. According to the information displayed on screen, the message was sent on Monday, June 22, 2026, for a video conference scheduled for Wednesday, June 24, 2026, at 12:00 p.m. Athens time. The link led to the official Webex domain of the Greek Prime Minister’s Office: greekpmgov.webex.com. The access code, the password, was a single sequence: 24022026.
This is where everything begins. However, the code 24022026 does not correspond to the date of the meeting, June 24. Instead, it corresponds to February 24, 2026. In other words, an invitation sent in June had a password based on a date from four months prior. This leads us to a reasonable conclusion: the virtual meeting room was not created specifically for this session. In fact, all the evidence suggests that it was created in late February and has been reused ever since with the same meeting ID and password.
To understand the technical significance of this, it is important to note that Webex offers two main types of meeting. The first is the Personal Room, which is a permanent personal meeting space. The meeting ID and link remain fixed unless manually altered by the administrator. The second type is the Scheduled Meeting. If it is a one-off meeting, the ID ceases to function once the session has ended. However, if configured as a recurring meeting, the same ID and password remain valid for every meeting in the series while the virtual room is active.
Apart from Mr Carrasco, the expert consulted by the Data Journalists personally entered the meeting ID into the Webex platform without attempting to join the meeting. The result was revealing: the virtual meeting room appears to still be active and continues to prompt users for the password. This strongly suggests that the room is configured as either a recurring or permanent meeting space, and that it was most likely created in February 2026, as the password itself suggests. Despite the international embarrassment caused by the incident, at the time of writing, it seems that those responsible have not even bothered to delete it.
What basic digital security requires
Let us stick to the technical facts, because that is where every justification based on sophisticated deepfakes falls apart. Regardless of whether the person on the other end was an AI-generated deepfake or two individuals in disguise, the information provided by MEGA itself suggests a lack of basic digital security awareness.
Firstly, using a password based on a date instead of generating one randomly with a password generator is, by definition, poor security practice. A password such as ‘24022026’ can be guessed in a matter of seconds.
Secondly, using the same virtual meeting room with the same meeting ID and password for months means access was open and exposed for weeks, if not months. If this is the case, the obvious question is: who else could have joined, listened to or recorded sensitive conversations without being detected?
Thirdly, even after such an internationally publicised scandal, a high-level meeting room used for discussions involving the National Security Adviser was not deleted. The fact that it remained active days later speaks for itself.
The questions that demand a public answer
- Who decided to use a simple date as the password for a high-level meeting, and what was the technical basis for this decision?
- If the meeting room had been configured as recurring since February, how many times was it used with the same password thereafter?
- Had the prank never occurred, how much longer would that password have remained valid? More troublingly, could it still be valid today?
Those concerned should therefore disregard the media spin about supposedly highly sophisticated deepfakes, claims that are contradicted by Federico Carrasco’s technological analysis.




