Key Moments:
- High-stakes online poker players reported malware that allowed real-time remote viewing of their screens and hole cards.
- Jurojin Poker confirmed that an attacker replaced user updates with software granting unauthorized remote access.
- Some platforms banned accounts tied to the incident, confiscated over $100,000, and reimbursed affected players.
Cyber-Attack Targets Elite Poker Players
High-stakes online poker faces a fresh security crisis after several notable players disclosed a sophisticated cyber-attack. Consequently, an unauthorized party deployed malware through compromised third-party tools that professionals favor for table organization and automation. As a result, this malware granted the attacker direct remote access to victims’ devices and private cards during live sessions.
Meanwhile, Jurojin Poker announced that an assailant intermittently distributed tampered software to select users. “This was a highly targeted operation, not a mass attack,” Jurojin stated. Furthermore, the company clarified that the cheater specifically targeted high-stakes opponents to monitor their gameplay unlawfully.
Impact and Mechanism of the Attack
Specifically, the malicious campaign exploited MeshCentral, a legitimate remote-management tool, by embedding its “Mesh Agent” within software updates. Therefore, once players installed the update, this agent allowed the operator to observe and control infected machines without the victims’ knowledge. For poker professionals, this breach meant an attacker could watch their face-down cards live and gain a critical edge.
In addition, cybersecurity researcher “WolfSec0x0” publicized the scheme and estimated that between 10 and 30 computers across Europe, North America, and Oceania suffered compromises. Jurojin reported that contaminated updates circulated sporadically between June 2025 and January 2026. However, the company asserted that the breach affected only a limited group of users, and it quickly reported the issue to clients and authorities.
Detection, Suspicion, and Platform Response
Subsequently, suspicion grew among high-stakes players who noticed improbably strong performances from certain accounts. For instance, PokerNews highlighted that the account “Paul Gregg” raised red flags among competitors before news of the malware became public. Additionally, poker coach Patrick Howard analyzed unusual results in September and asked GGPoker to investigate, although he stopped short of accusing the player directly.
Similarly, CoinPoker ambassador Patrick Leonard reported that the platform banned an account named “Europe,” which operated under the name Paul Gregg. CoinPoker then seized over $100,000 from the account and compensated impacted players. Meanwhile, high-stakes competitor Ignacio Morón reported personal losses between $100,000 and $200,000 to the suspect account, including a $60,000 loss in just fifteen minutes.
In response, ACR Poker announced a new “Screen Shield” feature to block screen-capture and screen-sharing utilities from accessing its tables.
Historical Context: Not the First Superuser Breach
Naturally, this episode echoes notorious breaches from the 2000s. For example, in 2007, players detected that the account “Potripper” generated implausible outcomes on Absolute Poker. Shortly after, the site acknowledged that seven rogue accounts participated in a forty-day cheating scheme, resulting in $1,600,000 in refunds. Eventually, investigators traced the cheat to staff members who used “God Mode” to access all players’ hidden cards in real time. Although players widely linked the Potripper account to a top operations executive, no regulator officially disclosed the identity.
Furthermore, an even larger fraud ensnared Absolute Poker’s affiliate, UltimateBet. In that case, investigators concluded that former world champion and site consultant Russ Hamilton orchestrated an operation that exploited live access to opponents’ hidden cards.
Timeline of Key Events
| Event | Details |
|---|---|
| June 2025 – January 2026 | Attackers deployed malware-infected updates to a subset of high-stakes players using Jurojin Poker software. |
| September (year unspecified) | Poker coach Patrick Howard analyzes and reports suspicious account activity to GGPoker. |
| Subsequent to public discovery | CoinPoker bans the “Europe” account, seizes over $100,000, and reimburses affected users. |
- Author