Skip to content
Online Poker Hit by New 'Superuser' Scandal as Malware Exposes Players' Hole Cards

Online Poker Hit by New 'Superuser' Scandal as Malware Exposes Players' Hole Cards

Casino • October 5, 2026

High-stakes online poker has been rocked by a new superuser-style scandal after several top players fell victim to a malware attack that allowed a cheater to secretly view their screens and hole cards in real time.

The attacker is believed to have compromised third-party software used by high-volume online players to organize multiple poker tables, install hotkeys, and manage other aspects of their games.

Jurojin Poker, one of the software providers affected, acknowledged this week that an attacker was able to intermittently replace updates sent to a select group of users with tampered versions containing remote-access software.

“This was a highly targeted operation, not a mass attack,” Jurojin said. The company added that the attacker was a “known cheater” targeting specific high-stakes opponents with the aim of viewing their hole cards remotely.

A second popular poker-management program, IntuitiveTables, was also compromised, according to Jurojin and reports on the investigation. Neither company has been accused of knowingly participating in the scheme.

Watching From Inside the Computer

The malware was based on MeshCentral, legitimate remote-management software normally used by IT departments to access computers remotely.

Once installed, however, the hidden “Mesh Agent” could reportedly allow whoever controlled it to watch an infected player’s screen and operate the computer remotely. In an online poker game, that would provide an enormous advantage: the attacker could see an opponent’s face-down cards while the hand was being played.

Cybersecurity researcher “WolfSec0x0,” who first exposed the operation on X, initially identified between 10 and 30 affected computers across Europe, North America, and Oceania.

Jurojin said its own compromised updates were delivered intermittently between June 2025 and January 2026 and that only a small group of users was targeted. The company has contacted potentially affected customers and provided information to law enforcement and poker-site security teams.

‘Superuser’ Suspicions

The discovery adds weight to suspicions some high-stakes players have recently voiced certain accounts they believed were producing implausibly strong results.

PokerNews reported that an account using the name “Paul Gregg” had been flagged by players before the malware operation became public. Poker coach Patrick Howard reportedly sent GGPoker an analysis in September highlighting unusual results and asking the company to investigate, although he stopped short of accusing the player of cheating.

Meanwhile, CoinPoker ambassador Patrick Leonard said the site had previously banned an account called “Europe,” which he said was registered in Paul Gregg’s name, confiscating more than $100,000 and reimbursing affected players.

High-stakes player Ignacio Morón has claimed he lost between $100,000 and $200,000 playing against the suspect account, including $60,000 during one 15-minute session.

The revelations have already prompted at least one poker operator to change its software. ACR Poker said it has developed a “Screen Shield” designed to prevent its tables from being visible to screen-capture and screen-sharing programs.

Echoes of UltimateBet and “God Mode”

For veteran online poker players, the incident recalls the notorious superuser scandals of the late 2000s. In 2007, an account called “ Potripper ” was exposed by players on the TwoPlusTwo forums after producing implausibly successful results on Absolute Poker.

Absolute Poker later acknowledged that seven accounts had been used to cheat players over a 40-day period and promised $1.6 million in refunds.

Investigators determined that insiders had access to software capable of revealing opponents’ hole cards in real time—a capability players dubbed “God Mode.” The Potripper account was subsequently widely linked to a former Absolute Poker director of operations, although regulators never publicly identified its operator.

A similar and much larger scandal emerged at Absolute Poker’s sister site, UltimateBet. Investigators identified former WSOP Main Event champion and UltimateBet consultant Russ Hamilton as the primary offender in a scheme that likewise exploited access to opponents’ hidden cards.

In Philip Conneller’s eight years with Casino.org, he has covered the gaming industry from Las Vegas to Macau and everything in between. He currently focuses his coverage on gaming law, white-collar crime, global money laundering, tribal gaming, politics, and regulation.

Philip was the original features editor for poker’s Bluff Magazine and editor for Bluff Europe, which he helped launch. His writing has also been featured in ESPN, Forbes, Time Out, The Sun, and The Daily Star, as well as iGaming Business, eGaming Review, and numerous other industry news and tech websites.

His news stories for Casino.org/news have been linked by The Washington Post, The Daily Mail, People Magazine, and Jimmy Fallon's Tonight Show, among many others.

Philip once won $20,000 with 7-2 off-suit. He has been reprimanded for unwittingly playing Elton John’s piano on two separate occasions on both sides of the Atlantic.

He became a writer because he is a lousy pianist.

Philip lives outside London with his wife and children, where he spends his time agonizing Arsenal FC.

Philip at [email protected].

Be the first to on this article.

Extracted Entities