Last Updated on October 10, 2026 by Bala Kumar
Most poker players install a HUD or table manager without a second thought. It sits quietly in the background, tiles your tables, saves your hands and makes long sessions easier. This autumn, that trust was turned into a weapon.
Jurojin Poker, one of two table-management programs caught up in online poker’s latest superuser scandal, has now apologised to its users. The company says an attacker slipped tampered updates to a select group of customers, installed hidden remote-access software on their computers, and used it to watch high-stakes players’ hole cards in real time. Below, we break down what happened, who was hit, how the sites responded and, most importantly, what you should do to protect yourself.
What Is a “Superuser” in Online Poker?
A superuser is a player who can see information nobody else at the table can, usually their opponents’ face-down cards. Imagine playing a hand where the person across from you already knows you hold a busted draw. Every bluff fails, every value bet gets folded to, and every marginal call against you is perfectly timed.
In past scandals, superusers were insiders at the poker site itself. What makes the 2026 case different is that the poker sites were never hacked. The attacker went after the players’ own computers instead, through software those players trusted and installed willingly.
How the Attack Worked, in Plain English
Security experts call this a supply-chain attack. Rather than breaking into thousands of machines, the attacker compromised a single trusted source, a software update, and let the victims install the malicious code themselves.
1. A tampered update went out. According to Jurojin, a selected group of users received modified versions of the software instead of the genuine update. This happened intermittently between June 2025 and January 2026.
2. Hidden spyware was installed. The tampered update quietly added a program called Mesh Agent. It is built on MeshCentral, a legitimate remote-management tool that IT teams use to fix computers from a distance, which made it less likely to look suspicious.
3. The attacker watched the screen. Mesh gave the attacker the ability to view, and even control, the infected computer. During a session, that meant seeing the victim’s hole cards as they were dealt.
4. The attacker played against the victim. With a player’s cards visible, the attacker could sit at the same table on another account and play almost perfectly against them.
5. The trail was hidden. Jurojin says the attacker moved users in and out of update groups quickly, which made the activity hard to spot. Some early cases were wrongly blamed on people selling pirated copies of the software.
| 🔍 Why This Matters for Every Online PlayerThe poker room’s security can be flawless and you can still be cheated if your own computer is compromised. Any program that can see your screen, from a HUD to a remote-desktop app to a screen recorder, is a potential window into your hole cards. |
Timeline: From First Suspicions to the Apology
| Date | What Happened |
| Jun 2025 – Jan 2026 | Tampered Jurojin updates delivered intermittently to a selected group of users, according to the company. |
| Years earlier | Players say they raised suspicions about the same suspect account with poker sites long before the scandal broke; one site banned it and confiscated more than $100,000. |
| September 2026 | Poker coach Patrick Howard sends GGPoker an analysis of unusual results from a suspicious account and asks for an investigation. |
| Late September 2026 | Cybersecurity researcher WolfSec0x0 (“Wolf”) publishes his findings, initially identifying 10 to 30 infected computers across Europe, North America and Oceania. |
| September 30, 2026 | The suspected superuser attack is reported publicly in the poker media. |
| October 1, 2026 | Jurojin issues its first statement, calling the attack highly targeted rather than a mass infection. |
| October 9, 2026 | Jurojin answers detailed questions, apologises to affected users and outlines its fixes. |
What Jurojin Is Saying Now
Jurojin’s latest comments are part apology, part explanation and part pointed reminder about who else bears responsibility. Here are the key points, in our words:
• It was targeted, not random. The company says it now understands this was a deliberate operation against specific players, not the work of software pirates, as it had previously assumed for some incidents.
• Its security was weaker at the time. Jurojin admits the attack happened during a period when its own protections were not as strong as they are today.
• It found out the same way you did. The company says it learned of the scheme through Wolf’s investigation and the suspicions raised by high-stakes players.
• Fixes are in place. Jurojin has published a security notice, added new internal checks to block similar tampered updates, and turned off automatic periodic saving of hand histories, so hands are now saved manually only.
• Victims are being contacted. It has a list of users confirmed to have been in affected update groups at specific times and is notifying them directly, while warning that the list may not be complete.
• Authorities have been told. Reports have been filed with international authorities in the region where Jurojin believes the attacker operated, and detailed findings have been shared with poker sites’ security teams.
• The sites must step up. Jurojin says it wants victims repaid and argues that the poker rooms, which have access to game data, carry a major responsibility for spotting suspicious play and returning funds.
Who Was Hit, and How Badly?
By Jurojin’s own assessment, the risk falls sharply as stakes go down. The attacker had a limited number of infected machines to work with and focused on players with the most money on the table.
| Stakes Level | Risk of Being Sniped | Risk of Infection | What to Do |
| High stakes | Highest; main target | Possible if you used affected versions | Wipe and reinstall your PC; contact the sites you play on |
| Mid stakes | Lower, but some cases | Possible | Wipe and reinstall, or run Jurojin’s Mesh check tool |
| Low stakes | Very low | Still possible | Run the Mesh check tool at minimum |
High-stakes regular Ignacio Morón has said he believes he lost between $100,000 and $200,000 to the suspect account, including roughly $60,000 in a single 15-minute session. That figure is his own estimate and has not been independently confirmed.
How the Poker Sites Have Responded
| Operator | Reported Response |
| CoinPoker | Banned an account called “Europe,” registered under the name Paul Gregg, confiscated more than $100,000 and reimbursed affected players, according to its ambassadors. |
| GGPoker | Received a September warning about unusual results and contacted the coach who flagged it about an investigation. No outcome has been announced. |
| ACR Poker | Built a “Screen Shield” feature that blocks its tables from screen-capture and screen-sharing programs. |
The uneven response is part of the story. One site appears to have caught the account long before the scandal went public, but players say concerns were raised with operators for years. If you play on any of the bigger networks, our GGPoker review and top poker sites list are good places to compare how rooms handle security and player protection.
How This Compares to Poker’s Biggest Cheating Scandals
| Scandal | Year | Who Did It | How It Worked | Outcome |
| Absolute Poker (“Potripper”) | 2007 | Site insider | Superuser access to hole cards through the site’s own systems | Seven accounts over 40 days; $1.6 million refunded |
| UltimateBet | 2008 | Site insiders | Superuser accounts inside the site | Russ Hamilton named as the primary offender |
| Jurojin / IntuitiveTables | 2026 | Outside attacker | Tampered third-party software updates installed spyware on players’ PCs | Suspect account banned on one site; investigations ongoing |
The old scandals were about trusting the poker room. This one is about trusting everything else running on your computer. That makes it harder for sites to detect, and it means players now share responsibility for their own security.
Who Is Responsible?
There is no clean answer yet, and that is exactly why the debate has been so heated.
• The software company distributed the tampered updates and admits its security was weaker at the time. Its customers trusted it with deep access to their machines.
• The poker sites hold the hand data. A player winning at impossible rates while showing down hands that make no sense should, in theory, trigger their security teams. Players say warnings went unheeded for too long.
• The attacker is the one who cheated, and authorities have now been notified.
Our view: the fairest outcome is for sites to review the suspect accounts’ full histories and refund every player they can identify, regardless of which software was involved. One operator has already shown it can be done.
What You Should Do Right Now
Whether you played with Jurojin or not, this is a good moment for a security check. These steps take less than an hour and cost nothing.
1. If you used Jurojin or IntuitiveTables between June 2025 and January 2026, wipe your computer and reinstall the operating system from scratch. Jurojin itself recommends this.
2. If a full reinstall is not possible, run Jurojin’s Mesh check tool to see whether the hidden agent is still installed.
3. Check for unknown remote-access programs. Look through your installed programs and running services for anything named Mesh, MeshAgent or remote-desktop tools you do not recognise.
4. Change your passwords and turn on two-factor authentication for every poker and email account, ideally from a clean device.
5. Contact the sites you play on if you believe you lost money to a suspicious player. Give them dates, stakes and the opponent’s name.
6. Only install what you need. Every helper program is another door into your machine. Before adding any tool, check whether the site even allows it; our guide to real-time assistance and banned helper tools explains the rules.
7. Keep a record of your results. If something goes wrong, a clean session log makes it far easier to prove what you lost. Our roundup of the best bankroll tracking apps can help.
| 🛡 A Simple Habit Worth KeepingJurojin suggests a clean reinstall of your computer about twice a year as general good practice. For anyone playing real-money poker regularly, that is sensible advice, scandal or not. And if you prefer study tools that don’t need installing at all, our browser-based poker calculators and analysers run without any software on your machine. |
The Bigger Picture
Online poker has spent the last few years fighting bots and real-time assistance tools. The 2026 superuser case adds a new front: attackers who don’t need to beat the poker site at all, only the software sitting next to it.
Expect more rooms to follow ACR’s lead with screen-protection features, and expect software makers to face tougher questions about how they sign and verify updates. For players, the takeaway is simple. Your edge at the table starts with a clean machine. Keep following our poker news for updates as investigations and refunds develop, and remember that if poker ever stops feeling like a game, support is available.
FAQs
What is the 2026 online poker superuser scandal?
It is a cheating scheme in which an attacker used tampered updates of third-party poker software to install hidden spyware on players’ computers. The spyware let the attacker see victims’ hole cards and play against them with that information.
Which poker software was compromised?
Jurojin Poker and IntuitiveTables, two table-management programs, were both reported as compromised. Jurojin says tampered updates were sent to a selected group of users between June 2025 and January 2026.
What did Jurojin say about the attack?
Jurojin apologised to affected users, said the attack was highly targeted and happened while its security was weaker, and outlined fixes including new update checks. It also said poker sites carry major responsibility for returning players’ funds.
Were the poker sites hacked?
No. Reports indicate the poker sites themselves were not breached. The attacker targeted players’ own computers through compromised third-party software.
How do I know if my computer was affected?
If you used Jurojin or IntuitiveTables during the affected period, the safest step is to wipe and reinstall your computer. If that is not possible, run Jurojin’s Mesh check tool and look for unknown remote-access programs.
Will cheated players get their money back?
One site banned a suspect account, confiscated more than $100,000 and reimbursed affected players. Other operators have not announced refunds yet, so affected players should contact the sites they play on directly.

Founder of PokerClubGames.com and a Poker Researcher with 10+ years of experience in SEO, WordPress development, and gaming content strategy. Specializes in researching online poker sites, poker apps, tournaments, bonuses, and poker strategies. Experienced in poker platform reviews, affiliate marketing, and creating SEO-focused poker content for global audiences.
For collaborations, media inquiries, or poker-related partnerships:
Contact: partnerships@pokerclubgames.com


