Poker Sites Warned Over Link to Online Poker Cheating Scandal

Online Poker Cheating Scandal: How a Malware Attack Targeted High-Stakes Players and What It Means for the Industry

The online poker world is no stranger to controversy, but the recent revelations surrounding the “Paul Gregg” account have sent shockwaves through the community. What initially appeared to be a single cheater’s activity has now expanded into a full-blown cybersecurity scandal involving malware, compromised third-party software, and a coordinated effort to steal hole-card information from high-stakes players. This incident is a stark reminder of how vulnerable even the most secure online platforms can be when third-party tools and remote-access systems are weaponized.

Below, we break down the entire affair—from the initial attack vector to the industry-wide response—and examine what it means for poker operators, players, and the integrity of the game itself.


The Attack: Malware Hidden in Software Updates

How the Attack Worked

The core of this scandal revolves around a sophisticated malware operation that targeted high-stakes poker players by compromising their computers. The attackers used a technique known as a supply-chain attack, where malicious code is inserted into legitimate software updates. In this case, the attackers targeted two well-known third-party poker tools:

Both companies confirmed that the attack involved pushing altered updates to a limited number of users. Jurojin specifically stated that between June 2025 and January 2026, some users received malicious updates that, when installed, compromised their systems.

The Role of MeshCentral

The malware leveraged MeshCentral, a legitimate, publicly available remote-access tool. While MeshCentral is designed for IT professionals to remotely control computers, the attackers repurposed it for malicious ends. Once installed on a victim’s machine, the malware could:

This level of access is catastrophic in an online poker context. If an attacker can see a player’s hole cards before a decision is made, they effectively have an unbeatable edge. The fact that the tool is legitimate also makes detection more difficult, as it behaves like normal remote-management software.

A Targeted, Not Random, Attack

Cybersecurity researcher WolfSec0x0, who investigated the incident, estimated that only 10 to 30 computers were affected across several regions. This is a remarkably small number, indicating that the attack was highly selective. The attacker was not casting a wide net; they were specifically going after particular high-stakes players.

Jurojin Poker confirmed this assessment, noting that the attacker appeared to be targeting individuals with significant money at the tables and had previously been linked to other poker-related service compromises. The use of a narrow attack surface also helped the operation remain under the radar for months.


The Paul Gregg Account: A Pattern of Suspicion

Players Spotted the Anomalies Early

Before the malware story broke, players had already raised alarms about an account named “Paul Gregg.” Multiple users reported observing unusual betting patterns and game-play behavior associated with this account. These observations were not based on a single hand or a momentary lapse of judgment; they were consistent, strange patterns that stood out to experienced players.

One of the first to act was poker coach Patrick Howard, who sent a detailed analysis to GGPoker in September. Howard did not directly accuse the account holder of cheating, but he asked the operator to review the activity. GGPoker later confirmed that it had been in contact with Howard as part of its investigation. This type of proactive reporting from players is exactly how many poker scandals first come to light.

CoinPoker’s Swift Action

While GGPoker was still reviewing the information, another operator had already taken decisive action. CoinPoker reportedly detected suspicious activity associated with the same “Paul Gregg” identity, deleted the account, and seized more than $100,000 that was believed to be connected to the fraudulent play. Players who had been affected by the account were later reimbursed.

Patrick Leonard, a CoinPoker ambassador, revealed that the account had been on the platform for less than a week before it was flagged. He also noted that a larger group of players had complained about the account to various poker operators over the past few years. This suggests that the “Paul Gregg” identity may have been used across multiple sites, with some operators slower to act than others.

Financial Fallout for One Victim

The human cost of this scheme is best illustrated by Spanish professional Ignacio Morón. Morón estimates that he lost between $100,000 and $200,000 to the alleged account. In one particularly brutal 15-minute stretch, he lost roughly $60,000 —a loss that likely came as a direct result of the attacker seeing his hole cards.

Morón’s experience highlights why this scandal is so damaging. High-stakes players are not used to being outplayed; they are used to making mathematically sound decisions. When those decisions are based on incomplete or manipulated information, the psychological and financial toll is enormous.


Industry Response: Tighter Security and Damage Control

ACR Poker’s New Anti-Cheat Feature

In the wake of these revelations, some operators have moved quickly to introduce new protective measures. ACR Poker has rolled out a feature that blocks screen-sharing and screen-capture software from displaying its poker tables. This is a direct counter to the type of malware used in the attack, which relies on capturing or mirroring the screen to steal hole-card information.

While this feature is a step in the right direction, it is important to note that it is not a silver bullet. Malware that operates at the operating-system level can often bypass application-level blocks. Still, it raises the bar for attackers and forces them to develop more sophisticated techniques.

Calls for Better Third-Party Software Oversight

This incident has also reignited the debate over third-party poker tools. While programs like Jurojin and IntuitiveTables are extremely popular among serious players, they also represent a potential security risk. When a player installs a third-party application, they are essentially giving that developer full access to their computer—and, by extension, to their poker account and financial information.

Operators and regulators may need to consider implementing stricter certification standards for third-party software. In the meantime, players should exercise caution when downloading new tools and ensure that they are using the latest, verified versions.


A Dark History of Poker Cheating Scandals

The “Paul Gregg” incident is not an isolated event. Online poker has a long and unfortunate history of cheating scandals, many of which involved gaining unauthorized access to opponents’ hole cards.

The PotRipper Scandal at Absolute Poker

In 2007, a scandal erupted at Absolute Poker when a player named PotRipper was discovered to be using a superuser account. The account had the ability to see all opponents’ hole cards, allowing the player to make perfect decisions on every street. An internal investigation later confirmed that the cheating was carried out by a former Absolute Poker employee.

The Russ Hamilton and UltimateBet Case

Around the same time, UltimateBet was involved in a similar scandal. Russ Hamilton, a poker pro and former World Series of Poker champion, was accused of using his access to the site’s database to view opponents’ hole cards. The scheme cost players millions of dollars and did enormous damage to the reputation of the site, which eventually ceased operations.

The Lasting Impact on Player Trust

These historical cases share a common thread with the current scandal: they all involved a breach of the fundamental principle of fair play. When players lose money to a cheater, they don’t just lose cash—they lose confidence in the entire ecosystem. That loss of trust can take years to rebuild.


What Players Can Do to Protect Themselves

While the primary responsibility for security lies with poker operators and software developers, individual players can take steps to reduce their exposure to similar attacks:


The Road Ahead for Online Poker Security

The “Paul Gregg” scandal is a wake-up call for the entire online poker industry. While the attack was limited in scope, the potential for larger-scale damage is clear. Poker sites must invest in better security infrastructure, foster stronger relationships with third-party software vendors, and take player reports of suspicious activity more seriously.

For players, the message is simple: stay vigilant. The tools that make online poker more enjoyable can also become vectors for attack. By understanding the risks and taking proactive measures, the community can help ensure that the games remain fair, secure, and enjoyable for everyone.