
A major online poker superuser scandal has erupted after compromised third-party poker software allegedly allowed an attacker to watch high-stakes players’ screens and see their hole cards in real time.
The story began as a cybersecurity investigation. However, it quickly developed into one of the biggest online poker security stories of 2026.
Two popular third-party poker tools, Jurojin Poker and IntuitiveTables, have been identified in reports about compromised software builds.
The poker rooms themselves are not currently believed to have been hacked.
Instead, malicious software was reportedly delivered to a small group of players through trusted third-party applications running alongside their poker clients.
That distinction is critical.
If an attacker can see a player’s screen, they can potentially see the player’s private hole cards without breaking into the poker room itself.
Reports indicate that approximately 10 to 30 high-stakes players may have been affected across different regions.
Meanwhile, several poker professionals have publicly described suspicious losses, and accounts connected in community reports to the investigation have played on networks including GGPoker, Winning Poker Network and CoinPoker.
One operator reportedly confiscated more than $100,000 from a suspicious account and refunded affected players.
By October 2, the story had moved beyond a technical malware investigation.
Poker rooms were facing questions about previous warnings, players were reviewing old databases, and ACR Poker announced a new Screen Shield security feature in response.
Here is what we currently know about the online poker superuser scandal, what remains unproven, and what regular poker players should do now.
Online Poker Superuser Scandal: Quick Facts
| Question | Current Information |
|---|---|
| What happened? | Compromised third-party poker tools reportedly delivered remote-access software to selected players |
| Tools Identified | Jurojin Poker and IntuitiveTables |
| Players Reportedly Targeted | Approximately 10 to 30, mainly high-stakes players |
| Main Risk | Remote viewing of screens and potentially hole cards |
| Were Poker Sites Hacked? | No poker-room client compromise has been established |
| Type of Attack | Targeted third-party software compromise |
| Jurojin Incident Window | Vendor’s updated notice says June 2025 to January 2026 |
| Known Security Response | Jurojin security changes and ACR Screen Shield |
| Account Publicly Discussed | “Europe” on CoinPoker, plus other accounts named in community reports |
| Confiscation Reported | More than $100,000 from the CoinPoker account, according to player and ambassador reports |
What Happened in the Online Poker Superuser Scandal?
The attack appears to have targeted the player’s computer rather than the poker server.
That is what makes the case unusual.
Normally, online poker cheating discussions focus on bots, collusion, multi-accounting or real-time assistance.
This case introduced another threat.
An attacker could potentially gain access to a player’s Windows computer and watch what appeared on the screen.
During an online poker session, that screen contains information opponents are never supposed to see.
Most importantly, it contains the player’s hole cards.
Therefore, a person with hidden remote-screen access could theoretically know an opponent’s exact hand while playing against them.
That would create an enormous unfair advantage.
For comparison, our Poker Bots and RTA in 2026 guide explains traditional software-assisted cheating. This incident is different because the reported advantage came from spying on an opponent’s machine.
Jurojin Poker Confirms a Targeted Security Incident
Jurojin has now published its own security notice.
The company says an attacker was able to intermittently replace update packages sent to one specific group of Jurojin users.
Some of those packages contained remote-access software.
Importantly, Jurojin describes the incident as a highly targeted operation, not a mass attack against its entire user base.
The company says the attacker was targeting particular poker opponents, mostly in high-stakes games.
That means a normal Jurojin user should not automatically assume their computer was infected.
However, players who were directly contacted by the company should take the incident seriously.
Jurojin’s Updated Timeline Matters
There has been some confusion about the dates.
Early poker-media reports described malicious Jurojin updates extending into June 2026.
However, Jurojin’s updated official security notice currently states that its affected update period ran from June 2025 through January 2026.
The company says nothing further was uploaded to its servers after January 28, 2026.
That newer vendor statement should be treated as the most direct source for Jurojin’s own timeline.
Still, the broader investigation covers activity involving more than one tool, so reports about earlier or later activity should not automatically be treated as contradictions.
IntuitiveTables Was Also Identified
Jurojin was not the only poker utility named in the investigation.
IntuitiveTables has also been identified as one of the applications targeted by the same wider operation.
Both programs are designed to improve the online multitabling experience.
They can help players arrange tables, use hotkeys and manage large poker sessions more efficiently.
That explains why high-volume professionals use this category of software.
Unfortunately, it also shows why trusted third-party utilities can become valuable targets for attackers.
What Was the Remote-Access Software?
Security reporting connected the incident to a remote-management agent based on MeshCentral technology.
Remote-management software is not automatically malicious.
Companies use similar tools every day for legitimate IT administration.
The danger appears when software is installed or controlled without the computer owner’s informed permission.
In this case, reports say the hidden agent could provide remote visibility into an affected Windows machine.
That makes poker uniquely vulnerable.
Watching a spreadsheet is one thing.
Watching an online poker table exposes information worth enormous amounts of money.
Why Seeing Hole Cards Is So Powerful
Poker is built around incomplete information.
Your opponent knows their cards.
You know yours.
Neither player should know the other’s private hand.
Strategy exists because players must estimate ranges instead of seeing the answer.
Now imagine removing that uncertainty.
If someone knows you have a bluff, they can call.
If they know you have the nuts, they can fold.
If they know you missed a draw, they can apply pressure.
Even a player with average strategic ability would gain a devastating edge if they could see an opponent’s cards.
This is why superuser-style allegations create such a serious trust problem for online poker.
Is This the Same as a Poker Bot?
No.
A poker bot automates gameplay or decision-making.
Real-time assistance provides strategic information during active play.
A remote-access attack is different again.
| Threat | What It Does |
|---|---|
| Poker Bot | Automates some or all poker decisions |
| RTA | Provides outside strategic assistance during play |
| Collusion | Players secretly coordinate or share information |
| Remote-Access Attack | Potentially lets an attacker view private information on another player’s computer |
| Superuser-Style Advantage | Opponent gains access to information they should never possess |
The categories can overlap in their effect, but the technical methods are different.
Were GGPoker, ACR or CoinPoker Hacked?
There is currently no public evidence showing that the poker clients themselves were breached in this incident.
That is an important distinction.
Players reportedly encountered suspicious accounts while competing on major poker networks.
However, the security compromise described by researchers involved third-party software on players’ computers.
Therefore, saying “GGPoker was hacked” or “ACR was hacked” would not accurately describe the information currently available.
The attack appears to have bypassed the need to compromise a poker room directly.
Why This Attack Model Is So Dangerous
Poker sites spend enormous resources protecting their own infrastructure.
They monitor account behavior, devices, login locations and suspicious game patterns.
However, every extra program running beside a poker client creates another possible attack surface.
A player can have a secure poker account and still use an insecure computer.
Likewise, a legitimate tool can become dangerous if its update infrastructure is compromised.
That is why players should evaluate third-party software just as carefully as the poker room itself.
Our Best HUDs for Online Poker 2026 guide explains why site rules and software trust should be checked before installing poker tools.
How Many Players Were Affected?
Public estimates have generally placed the affected group somewhere between 10 and 30 computers or players.
PokerNews reported that around 30 high-stakes players were known to have been targeted.
Other security reporting has used a range of 10 to 30.
The exact total may change as the investigation continues.
Therefore, players should avoid treating any current number as a final confirmed victim count.
Why High-Stakes Players Were Targeted
The economics are obvious.
A criminal targeting a micro-stakes player may gain very little.
A successful attack against somebody playing $25/$50, $50/$100 or higher can be worth dramatically more.
High-stakes regulars also play large volumes.
That creates repeated opportunities for an attacker to sit across from the same victim.
Consequently, a small number of targeted computers could potentially create very large financial damage.
Who Is Paul Gregg and What Has Been Alleged?
This part requires careful wording.
Several public poker reports and player statements have connected a player named Paul Gregg and a number of online screen names to the wider investigation.
Those links should be described as allegations and reported associations, not as a final legal finding.
Poker media has reported that accounts discussed by the community appeared across several networks.
One CoinPoker account, “Europe,” became particularly important because the site reportedly took action against it.
However, claims connecting every named account to one person or to every compromised machine remain part of an ongoing investigation.
CoinPoker Reportedly Confiscated More Than $100,000
According to statements reported by poker media, CoinPoker identified suspicious activity involving the “Europe” account.
The operator banned the account.
It also reportedly confiscated more than $100,000 and returned money to affected players.
CoinPoker ambassador Patrick Leonard later discussed the case publicly.
The important point is not only the amount.
The action suggests that suspicious gameplay had already attracted attention before the full malware story became public.
Poker Sites Were Reportedly Warned Earlier
This became one of the biggest developments on October 2.
New reporting said multiple poker sites had previously received concerns about suspicious high-stakes accounts.
That raises a wider question.
How quickly should a poker room respond when a group of respected high-stakes players reports statistically unusual behavior?
A strange win rate is not proof of cheating.
Neither is an unusual showdown.
However, repeated complaints can justify deeper investigation.
Why Impossible-Looking Win Rates Matter
Online poker security teams have access to information normal players do not.
They can review large hand samples.
They can analyze opponent selection.
They can compare session patterns.
They can also study unusual folds, calls and river decisions.
One strange hand proves almost nothing.
Thousands of strange hands may tell a different story.
That is why our guide to population reads in online poker emphasizes large samples instead of dramatic single-hand conclusions.
ACR Responds With Screen Shield
The story produced a direct operator response on October 2.
ACR Poker CEO Phil Nagy announced a feature called Screen Shield.
The system is designed to prevent Winning Poker Network tables from appearing inside certain screen-capture and screen-sharing tools.
The logic is straightforward.
If malicious software cannot easily capture the poker table, it becomes harder to use remote viewing to see private cards.
No security feature can guarantee perfect protection.
Still, this is an important example of a poker operator changing its product in response to a newly exposed threat.
Why Screen Capture Has Become a Poker Security Issue
Streaming culture makes the problem complicated.
Legitimate poker players regularly capture their screens.
They stream tournaments.
They record educational videos.
Coaches review sessions.
Content creators produce hand breakdowns.
Therefore, poker clients cannot simply assume that all screen-capture software is malicious.
The challenge is separating legitimate broadcasting from hidden surveillance.
Does This Mean Third-Party Poker Tools Are Unsafe?
No.
That conclusion would be too broad.
Thousands of players use legitimate third-party tools every day.
Many HUDs, table managers and study programs have existed for years without incidents like this one.
However, the scandal demonstrates that software trust is not binary.
A legitimate application can still become a target.
Therefore, players should think about software security as an ongoing process.
What Online Poker Players Should Do Now
If you never used the affected applications, there is no reason to assume this particular incident infected your computer.
However, every serious online player can learn from it.
1. Keep Poker Software Updated
Use current official versions of your poker clients and approved utilities.
Avoid downloading old installers from random mirrors.
2. Download Tools Only From Official Sources
Do not install poker utilities from unknown Telegram links, Discord attachments or file-sharing websites.
Phishing sites can imitate legitimate poker software.
3. Take Vendor Security Warnings Seriously
If a software company tells you directly that your machine may have received a compromised build, do not ignore the email.
Follow the vendor’s official remediation guidance.
4. Use a Clean Device to Change Important Passwords
If you genuinely suspect computer compromise, changing passwords on the same potentially compromised machine can defeat the purpose.
Use a known-clean device instead.
5. Enable Two-Factor Authentication
Two-factor authentication adds another barrier if a password is exposed.
Use it on poker accounts, email accounts and financial services where available.
6. Review Active Sessions
Check whether important accounts provide an option to log out other devices or revoke sessions.
This can help invalidate old sessions after credentials are changed.
7. Preserve Evidence Before Deleting Everything
If you believe you were directly affected, save relevant logs, emails, transaction records and hand histories before wiping the machine.
Security teams may need that information.
Should Affected Players Reinstall Windows?
Jurojin’s current security notice takes a cautious position.
The company says users who want to be extra safe can format their PC.
A clean operating-system installation is much more disruptive than simply uninstalling one application.
However, if a machine genuinely had unauthorized remote-access software with elevated privileges, a clean rebuild can provide stronger assurance than trying to guess what was modified.
This advice mainly applies to players who have evidence that their machines were affected.
It should not cause every online poker player to erase their computer.
Protect the Email Account Behind Your Poker Accounts
Your email can be more valuable than your poker password.
Password resets often pass through email.
Therefore, an attacker with email access may be able to reset credentials on multiple services.
Use a unique password and enable 2FA.
In addition, review recovery addresses and active login sessions.
Our Mobile Poker Security guide covers several practical account-protection habits that apply across poker platforms.
Do Not Confuse Malware With a Rigged RNG
This scandal will inevitably increase searches asking whether online poker is rigged.
However, the two issues are different.
A compromised player’s computer does not prove that a poker site’s random-number generator was manipulated.
Likewise, an opponent seeing another player’s screen does not require changing the cards being dealt.
The unfair advantage comes from hidden information.
Our Is Online Poker Rigged in 2026? guide explains why RNG integrity, cheating, bots and variance should be analyzed separately.
Why This Is More Serious Than a Normal Cheating Allegation
Most poker cheating accusations begin with gameplay.
Someone makes an impossible call.
A win rate looks suspicious.
A player notices strange timing.
Those clues can have innocent explanations.
This investigation is different because security researchers and affected software companies have discussed an actual third-party software compromise.
That does not prove every accusation against every named poker account.
Still, it moves the story beyond pure speculation.
Could This Happen to Low-Stakes Players?
Technically, attackers can target computers at any stake.
Economically, high-stakes players are more attractive targets.
The current incident was described as highly selective.
Therefore, there is no evidence of a mass campaign against ordinary $0.05/$0.10 players.
Nevertheless, basic security remains valuable at every stake.
A compromised computer can expose much more than poker cards.
Why Online Poker Players Install So Many Tools
Modern grinders may use several applications at once.
A typical setup can include:
- a poker client;
- a HUD or tracker;
- a table-management tool;
- hotkey software;
- streaming software;
- database software;
- note-taking tools;
- and communication apps.
Each additional application adds functionality.
It also creates another piece of software that needs updates and security review.
HUDs Are Not the Same as Malware or RTA
The scandal may cause some players to panic about every poker tool.
That would be a mistake.
A HUD that is explicitly allowed by a poker room is not automatically cheating.
Likewise, a table manager can be a legitimate productivity tool.
The question is whether the platform permits it and whether the software itself can be trusted.
Our online poker HUD guide explains why the rules differ between sites.
ClubGG Players Should Understand the Same Principle
This specific investigation is not evidence that ClubGG was compromised.
However, the security lesson applies to private-club poker too.
Players should avoid unauthorized software that claims to automate decisions, reveal hidden information or provide prohibited real-time assistance.
Our ClubGG Anti-Cheat and Fair Play guide covers the wider technology and rules around bots, RTA and suspicious behavior.
You can also review our ClubGG Fair Play Policies guide for a detailed breakdown of prohibited assistance and account responsibilities.
Anonymous Poker Does Not Solve This Problem
Anonymous tables can reduce tracking and long-term targeting based on a public screen name.
However, anonymity alone cannot secure an infected computer.
If malicious software can see the local screen, changing the visible opponent name does not remove the underlying device risk.
Anonymous pools have different strategic and privacy advantages, which we explain in our Anonymous Online Poker Pools guide.
What Poker Sites Can Learn From the Scandal
The first lesson is that anti-cheat systems cannot focus only on the poker client.
Modern poker security needs to consider the wider device environment.
Second, player reports matter.
One complaint may be noise.
Repeated complaints from strong players about the same account deserve attention.
Third, cross-site cooperation may become increasingly important.
An account that looks suspicious on one network could have relevant history elsewhere.
Could Screen Shield Become an Industry Standard?
ACR’s response may be watched closely by other operators.
If Screen Shield reduces unauthorized capture without breaking normal gameplay, similar technology could become more common.
However, poker sites also need to support legitimate streaming and content creation.
Therefore, implementation will require balance.
The industry needs to make hidden surveillance harder without making normal broadcasting impossible.
Why This Scandal Could Change Third-Party Tool Policies
Poker rooms already restrict some software based on strategic assistance.
After this incident, security risk may become another factor.
A room could become more cautious about unsigned tools, obscure utilities or applications with broad system permissions.
Operators may also demand stronger security practices from approved third-party developers.
That could include code signing, update verification and better logging.
What About the Players Who Lost Money?
This may become the most difficult part of the story.
If an opponent cheated using information obtained from infected computers, calculating the true loss is complicated.
Tracked poker results show who won money.
They do not automatically prove which individual pots were affected by hidden information.
Sites may therefore need to combine game data, security logs and malware timelines.
Refunding players fairly could require reconstructing sessions over long periods.
Do Huge Win Rates Prove a Superuser?
No.
An extraordinary win rate is evidence worth investigating, not proof by itself.
Poker contains variance.
Small samples can create strange results.
Meanwhile, elite players can outperform weaker pools significantly.
However, an extreme win rate combined with security evidence, unusual opponent selection and suspicious showdown decisions becomes more meaningful.
The evidence needs to be evaluated together.
Why Players Should Avoid Public Witch Hunts
The poker community moves quickly when cheating allegations appear.
That speed can help expose real problems.
It can also produce incorrect accusations.
Therefore, screen names, databases and social-media claims should not be treated as final proof without supporting evidence.
This is especially important when a real person’s identity is being discussed.
Operator findings and forensic evidence carry more weight than speculation.
Could This Hurt Trust in Online Poker?
Yes, although the long-term impact will depend heavily on how operators respond.
Online poker requires players to trust several systems at once.
They trust the cards.
They trust the operator.
They trust their device.
And many players trust additional third-party software.
A failure in any one of those layers can damage confidence in the whole experience.
Our State of Online Poker in 2026 looks at how security, liquidity and technology are reshaping the wider market.
Why Transparency Matters More Than Silence
Security incidents are damaging.
Hiding them can be worse.
Players need enough information to understand whether they were exposed and what they should do next.
Jurojin has published an incident notice and described security changes.
Meanwhile, ACR has publicly announced a technical response.
Those actions give the community something concrete to evaluate.
Other operators connected to the wider investigation may face pressure to explain what they found and when they found it.
Timeline of the Online Poker Malware Scandal
| Date | Development |
|---|---|
| 2024 | Security researchers later report earlier activity connected to the broader remote-access investigation |
| June 2025 | Jurojin says its affected update period began |
| January 28, 2026 | Jurojin’s updated notice says the last compromised file on its infrastructure was replaced |
| September 29, 2026 | Cybersecurity allegations become public and spread rapidly through the poker community |
| September 30 to October 1 | Jurojin and reports surrounding IntuitiveTables provide more information about compromised third-party software |
| October 2 | New reporting says poker sites had previously received warnings about suspicious accounts |
| October 2 | ACR announces Screen Shield as part of its security response |
Online Poker Superuser Scandal FAQ
What is the 2026 online poker superuser scandal?
It is an ongoing security and cheating investigation involving compromised third-party poker software that reportedly installed remote-access tools on selected high-stakes players’ computers.
Could the attacker see hole cards?
Reports indicate that remote screen access could expose whatever appeared on an affected player’s monitor, including private hole cards during online poker sessions.
Was Jurojin hacked?
Jurojin says an attacker was able to intermittently replace update packages delivered to a specific group of users. The company describes the incident as targeted rather than a mass compromise.
Was IntuitiveTables affected?
Yes. IntuitiveTables has also been identified in reporting and vendor communications as one of the third-party tools targeted in the broader operation.
Were GGPoker servers hacked?
No compromise of GGPoker’s poker client or servers has been established in the public reporting about this incident.
Was ACR Poker hacked?
No poker-client breach has been established. Reports focus on compromised software running on individual players’ computers.
Was CoinPoker hacked?
The current story does not establish a compromise of CoinPoker’s client. CoinPoker reportedly identified and banned a suspicious account and refunded affected players.
How many players were targeted?
Public reports have estimated approximately 10 to 30 affected or targeted high-stakes players. The final number may change as the investigation develops.
Who is Paul Gregg?
Poker reports and community investigations have publicly linked a player with that name to several allegations and suspicious accounts. Those claims should remain described as allegations unless confirmed through definitive operator or legal findings.
How much money was confiscated?
Reports say CoinPoker confiscated more than $100,000 from the “Europe” account and returned money to affected players.
What is ACR Screen Shield?
Screen Shield is a newly announced security measure designed to prevent WPN poker tables from being visible through certain screen-capture or sharing tools.
Should every Jurojin user reinstall Windows?
No evidence suggests every user was compromised. Players directly identified as affected should follow official vendor guidance. Jurojin says users seeking maximum caution can consider formatting the affected PC.
Are HUDs unsafe now?
No. This incident does not prove that all HUDs or poker utilities are unsafe. Players should use reputable software, follow poker-room rules and download tools only from official sources.
Is this proof that online poker is rigged?
No. The incident concerns alleged cheating through compromised player devices. That is different from evidence that the poker game’s RNG or dealing system was manipulated.
Can low-stakes players be affected?
Any computer can theoretically be attacked. However, the publicly described operation appears to have focused heavily on selected high-stakes players rather than a mass group of ordinary users.
What should I do if I think my poker PC was compromised?
Stop using the affected machine for sensitive accounts, follow official security instructions, preserve relevant evidence, change important credentials from a known-clean device, enable 2FA and contact the relevant poker-room security team.
Final Thoughts: Online Poker Security Has a New Threat Model
The biggest lesson from the online poker superuser scandal is not that every poker player should panic.
The known attack appears to have been targeted.
The victim group was relatively small.
And there is currently no evidence that major poker-room clients themselves were compromised.
However, the method changes the security conversation.
Players have spent years worrying about bots.
They worry about collusion.
They worry about RTA.
Now there is another possibility to consider.
The poker room can be secure while the player’s own computer is not.
A trusted third-party program can become part of the attack path.
An opponent does not need to manipulate the deck if they can secretly see your cards on your screen.
That is why the industry’s response matters.
Jurojin has published information about the incident and strengthened its security procedures.
CoinPoker reportedly banned a suspicious account and refunded players.
ACR has responded with Screen Shield.
Meanwhile, players and operators continue reviewing historical activity.
The investigation is not finished.
More accounts may be examined.
More refunds could follow.
Additional security tools may appear.
For regular online players, the practical lesson is simpler.
Protect the computer as seriously as you protect the poker account.
Download fewer unnecessary tools.
Use official sources.
Keep software updated.
Enable strong account security.
And when suspicious behavior appears repeatedly, document it rather than dismissing it as another bad beat.
Online poker has always depended on hidden cards.
In 2026, protecting those cards now means protecting the screen that displays them too.
