Summary
The session’s core message is that coordinated information operations now sit in a “pre-intrusion” risk layer: before a cyber, political, or reputational crisis fully materializes, attackers may already be manipulating media, social platforms, ads, synthetic identities, and fake evidence to shape public perception. Mr. Kusyy framed the talk around AI-powered early warning tools for detecting coordinated information operations, fake news, and influence campaigns before they become major threats. He said the best way to understand this field is through concrete cases, and introduced four planned examples: two aimed at governments and citizens around elections, and two aimed at private companies, with some run by hostile states such as Russia and North Korea and others by smaller opportunistic players.
After briefly introducing his background as a Ukrainian AI engineer, former Grammarly machine-learning platform lead, and cofounder of LetsData, he described the monitoring approach behind the company’s Vantage platform. The platform scans 50 countries, more than 140 languages, and over 100 million open sources to identify deepfakes, AI-generated assets, bot accounts, synthetic identities, coordinated personas, and signs of amplification. The goal, as presented, is to distinguish deliberate manipulation from organic chatter, raise warnings on suspected information operations, and work with platforms and authorities to take down harmful content.
The first major case was Doppelganger, a heavily studied Russian state-linked operation discovered in 2022 by the Atlantic Council and EU DISINFOLAB and later documented by French, U.S., U.K., and other authorities. Mr. Kusyy explained that the operation creates pixel-perfect replicas of well-known media outlets such as NOS, NU, and BBC, fills them with mostly copied legitimate content plus selected fake articles, and uses typosquatted domains, geo-cloaking, bulletproof hosting, bots, pages, and ads to drive targeted audiences to disinformation. One example involved an AI-generated video and false claims that election ballots had been discarded, while the infrastructure showed harmless content to researchers outside the target geography.
He then emphasized how dramatically cheaper these campaigns have become. Investigations into 2015–2016 election-meddling campaigns estimated about 80 people and $1.25 million per month, while more recent AI-enabled operations can be run by far smaller teams. He cited CopyCop as a related campaign reportedly involving one front person, some support, developers, and many AI agents, producing 167 fake websites, nearly 50,000 articles, and over 1,000 fake TikTok journalists. The available transcript ends as he transitions from a Czech election manipulation case into how similar signatures, accounts, hostings, and code reappeared later for a broader campaign across countries including the U.K., Poland, and Czechia.
Key Topics
5 key topics from Andriy Kusyy at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Monitor coordination patterns, not only individual misleading posts.
- Preserve campaign signatures for future reuse detection.
- Check geo-cloaked domains from target locations during investigations.
- Track ad funnels that drive audiences to fake media replicas.
- Treat cheap AI-generated operations as accessible to smaller actors.
“So we are talking that it became 100 times cheaper in time.”

Andriy Kusyy
CEO and Co-Founder•LetsData
Up Next


Next in agenda
PQC: Who owns cryptography? When decisions outgrow IT

Related
Humor, The Secret Weapon for Cybersecurity Awareness
Rosanne Pouw

Related
