Compromised Poker Software on Superuser Scandal: ‘We Are Truly Sorry’

Last Updated on October 10, 2026 by Bala Kumar

Most poker players install a HUD or table manager without a second thought. It sits quietly in the background, tiles your tables, saves your hands and makes long sessions easier. This autumn, that trust was turned into a weapon.

Jurojin Poker, one of two table-management programs caught up in online poker’s latest superuser scandal, has now apologised to its users. The company says an attacker slipped tampered updates to a select group of customers, installed hidden remote-access software on their computers, and used it to watch high-stakes players’ hole cards in real time. Below, we break down what happened, who was hit, how the sites responded and, most importantly, what you should do to protect yourself.

What Is a “Superuser” in Online Poker?

A superuser is a player who can see information nobody else at the table can, usually their opponents’ face-down cards. Imagine playing a hand where the person across from you already knows you hold a busted draw. Every bluff fails, every value bet gets folded to, and every marginal call against you is perfectly timed.

In past scandals, superusers were insiders at the poker site itself. What makes the 2026 case different is that the poker sites were never hacked. The attacker went after the players’ own computers instead, through software those players trusted and installed willingly.

How the Attack Worked, in Plain English

Security experts call this a supply-chain attack. Rather than breaking into thousands of machines, the attacker compromised a single trusted source, a software update, and let the victims install the malicious code themselves.

1.     A tampered update went out. According to Jurojin, a selected group of users received modified versions of the software instead of the genuine update. This happened intermittently between June 2025 and January 2026.

2.     Hidden spyware was installed. The tampered update quietly added a program called Mesh Agent. It is built on MeshCentral, a legitimate remote-management tool that IT teams use to fix computers from a distance, which made it less likely to look suspicious.

3.     The attacker watched the screen. Mesh gave the attacker the ability to view, and even control, the infected computer. During a session, that meant seeing the victim’s hole cards as they were dealt.

4.     The attacker played against the victim. With a player’s cards visible, the attacker could sit at the same table on another account and play almost perfectly against them.

5.     The trail was hidden. Jurojin says the attacker moved users in and out of update groups quickly, which made the activity hard to spot. Some early cases were wrongly blamed on people selling pirated copies of the software.

🔍 Why This Matters for Every Online PlayerThe poker room’s security can be flawless and you can still be cheated if your own computer is compromised. Any program that can see your screen, from a HUD to a remote-desktop app to a screen recorder, is a potential window into your hole cards.

Timeline: From First Suspicions to the Apology

DateWhat Happened
Jun 2025 – Jan 2026Tampered Jurojin updates delivered intermittently to a selected group of users, according to the company.
Years earlierPlayers say they raised suspicions about the same suspect account with poker sites long before the scandal broke; one site banned it and confiscated more than $100,000.
September 2026Poker coach Patrick Howard sends GGPoker an analysis of unusual results from a suspicious account and asks for an investigation.
Late September 2026Cybersecurity researcher WolfSec0x0 (“Wolf”) publishes his findings, initially identifying 10 to 30 infected computers across Europe, North America and Oceania.
September 30, 2026The suspected superuser attack is reported publicly in the poker media.
October 1, 2026Jurojin issues its first statement, calling the attack highly targeted rather than a mass infection.
October 9, 2026Jurojin answers detailed questions, apologises to affected users and outlines its fixes.

What Jurojin Is Saying Now

Jurojin’s latest comments are part apology, part explanation and part pointed reminder about who else bears responsibility. Here are the key points, in our words:

•        It was targeted, not random. The company says it now understands this was a deliberate operation against specific players, not the work of software pirates, as it had previously assumed for some incidents.

•        Its security was weaker at the time. Jurojin admits the attack happened during a period when its own protections were not as strong as they are today.

•        It found out the same way you did. The company says it learned of the scheme through Wolf’s investigation and the suspicions raised by high-stakes players.

•        Fixes are in place. Jurojin has published a security notice, added new internal checks to block similar tampered updates, and turned off automatic periodic saving of hand histories, so hands are now saved manually only.

•        Victims are being contacted. It has a list of users confirmed to have been in affected update groups at specific times and is notifying them directly, while warning that the list may not be complete.

•        Authorities have been told. Reports have been filed with international authorities in the region where Jurojin believes the attacker operated, and detailed findings have been shared with poker sites’ security teams.

•        The sites must step up. Jurojin says it wants victims repaid and argues that the poker rooms, which have access to game data, carry a major responsibility for spotting suspicious play and returning funds.

Who Was Hit, and How Badly?

By Jurojin’s own assessment, the risk falls sharply as stakes go down. The attacker had a limited number of infected machines to work with and focused on players with the most money on the table.

Stakes LevelRisk of Being SnipedRisk of InfectionWhat to Do
High stakesHighest; main targetPossible if you used affected versionsWipe and reinstall your PC; contact the sites you play on
Mid stakesLower, but some casesPossibleWipe and reinstall, or run Jurojin’s Mesh check tool
Low stakesVery lowStill possibleRun the Mesh check tool at minimum

High-stakes regular Ignacio Morón has said he believes he lost between $100,000 and $200,000 to the suspect account, including roughly $60,000 in a single 15-minute session. That figure is his own estimate and has not been independently confirmed.

How the Poker Sites Have Responded

OperatorReported Response
CoinPokerBanned an account called “Europe,” registered under the name Paul Gregg, confiscated more than $100,000 and reimbursed affected players, according to its ambassadors.
GGPokerReceived a September warning about unusual results and contacted the coach who flagged it about an investigation. No outcome has been announced.
ACR PokerBuilt a “Screen Shield” feature that blocks its tables from screen-capture and screen-sharing programs.

The uneven response is part of the story. One site appears to have caught the account long before the scandal went public, but players say concerns were raised with operators for years. If you play on any of the bigger networks, our GGPoker review and top poker sites list are good places to compare how rooms handle security and player protection.

How This Compares to Poker’s Biggest Cheating Scandals

ScandalYearWho Did ItHow It WorkedOutcome
Absolute Poker (“Potripper”)2007Site insiderSuperuser access to hole cards through the site’s own systemsSeven accounts over 40 days; $1.6 million refunded
UltimateBet2008Site insidersSuperuser accounts inside the siteRuss Hamilton named as the primary offender
Jurojin / IntuitiveTables2026Outside attackerTampered third-party software updates installed spyware on players’ PCsSuspect account banned on one site; investigations ongoing

The old scandals were about trusting the poker room. This one is about trusting everything else running on your computer. That makes it harder for sites to detect, and it means players now share responsibility for their own security.

Who Is Responsible?

There is no clean answer yet, and that is exactly why the debate has been so heated.

•        The software company distributed the tampered updates and admits its security was weaker at the time. Its customers trusted it with deep access to their machines.

•        The poker sites hold the hand data. A player winning at impossible rates while showing down hands that make no sense should, in theory, trigger their security teams. Players say warnings went unheeded for too long.

•        The attacker is the one who cheated, and authorities have now been notified.

Our view: the fairest outcome is for sites to review the suspect accounts’ full histories and refund every player they can identify, regardless of which software was involved. One operator has already shown it can be done.

What You Should Do Right Now

Whether you played with Jurojin or not, this is a good moment for a security check. These steps take less than an hour and cost nothing.

1.     If you used Jurojin or IntuitiveTables between June 2025 and January 2026, wipe your computer and reinstall the operating system from scratch. Jurojin itself recommends this.

2.     If a full reinstall is not possible, run Jurojin’s Mesh check tool to see whether the hidden agent is still installed.

3.     Check for unknown remote-access programs. Look through your installed programs and running services for anything named Mesh, MeshAgent or remote-desktop tools you do not recognise.

4.     Change your passwords and turn on two-factor authentication for every poker and email account, ideally from a clean device.

5.     Contact the sites you play on if you believe you lost money to a suspicious player. Give them dates, stakes and the opponent’s name.

6.     Only install what you need. Every helper program is another door into your machine. Before adding any tool, check whether the site even allows it; our guide to real-time assistance and banned helper tools explains the rules.

7.     Keep a record of your results. If something goes wrong, a clean session log makes it far easier to prove what you lost. Our roundup of the best bankroll tracking apps can help.

🛡 A Simple Habit Worth KeepingJurojin suggests a clean reinstall of your computer about twice a year as general good practice. For anyone playing real-money poker regularly, that is sensible advice, scandal or not. And if you prefer study tools that don’t need installing at all, our browser-based poker calculators and analysers run without any software on your machine.

The Bigger Picture

Online poker has spent the last few years fighting bots and real-time assistance tools. The 2026 superuser case adds a new front: attackers who don’t need to beat the poker site at all, only the software sitting next to it.

Expect more rooms to follow ACR’s lead with screen-protection features, and expect software makers to face tougher questions about how they sign and verify updates. For players, the takeaway is simple. Your edge at the table starts with a clean machine. Keep following our poker news for updates as investigations and refunds develop, and remember that if poker ever stops feeling like a game, support is available.

FAQs

What is the 2026 online poker superuser scandal?

It is a cheating scheme in which an attacker used tampered updates of third-party poker software to install hidden spyware on players’ computers. The spyware let the attacker see victims’ hole cards and play against them with that information.

Which poker software was compromised?

Jurojin Poker and IntuitiveTables, two table-management programs, were both reported as compromised. Jurojin says tampered updates were sent to a selected group of users between June 2025 and January 2026.

What did Jurojin say about the attack?

Jurojin apologised to affected users, said the attack was highly targeted and happened while its security was weaker, and outlined fixes including new update checks. It also said poker sites carry major responsibility for returning players’ funds.

Were the poker sites hacked?

No. Reports indicate the poker sites themselves were not breached. The attacker targeted players’ own computers through compromised third-party software.

How do I know if my computer was affected?

If you used Jurojin or IntuitiveTables during the affected period, the safest step is to wipe and reinstall your computer. If that is not possible, run Jurojin’s Mesh check tool and look for unknown remote-access programs.

Will cheated players get their money back?

One site banned a suspect account, confiscated more than $100,000 and reimbursed affected players. Other operators have not announced refunds yet, so affected players should contact the sites they play on directly.

Leave a Reply

Your email address will not be published. Required fields are marked *

Poker Platform
Borgata Poker review: bonuses, games, app features, payments and tournament schedules for 2026.

Suprema Poker review covering its app features, games, ratings, updates, club-agent model, security, real-money risks, and India availability.

 
 

Bravo Poker Live review 2026: explore live poker games, waitlists, tournament clocks, features, ratings, and room coverage.

 
 
1Win Poker review 2026 covering bonuses, games, payments, mobile apps, licensing, and withdrawals.
Explore RedStar Poker’s $2,000 welcome bonus, up to 35% rakeback, iPoker games, traffic, software, and payment options in 2026.

Explore BetRivers Poker’s $1,000 bonus, low rake, multi-state games, app features, and payment options in 2026.