Last Updated on October 1, 2026 by Bala Kumar
SEO Setup
| Field | Value |
| SEO title | Online Poker Cyber Attack: Jurojin Explains the Hack (2026) |
| Meta description | Jurojin Poker confirms a year-long targeted attack let a cheater view high-stakes players’ hole cards. What happened, who was hit, and how to stay safe. |
| URL slug | /online-poker-cyber-attack-jurojin-statement |
| Focus keyword | online poker cyber attack |
| Secondary keywords | Jurojin Poker hack, online poker superuser scandal, poker cheating 2026, IntuitiveTables, hole cards exposed, poker software security |
| Long-tail keywords | is Jurojin Poker safe to use, how did hackers see poker hole cards, poker HUD malware, how to protect online poker account |
Use the focus keyword in the H1, the first 100 words, one H2 and the image alt text. Keep density near 1%.
Introduction
The biggest online poker cyber attack in years did not break into a poker site. It came through the tools players trust to run beside their tables.
On 30 September 2026, Jurojin Poker confirmed that an attacker had secretly swapped its software updates for a small group of users between June 2025 and June 2026. Some of those tampered updates carried a remote-access tool that let the attacker watch victims’ screens, including their hole cards. About 30 high-stakes players are known to have been targeted.
Here is what happened, what Jurojin says it has fixed, and what every online poker player should do now.
What Happened in the Online Poker Cyber Attack
The attack hijacked trusted poker tools, not poker sites. An attacker slipped a hidden remote-access agent onto players’ Windows PCs through tampered updates of third-party table-management software, then watched their screens live.
| Date | Event |
| 30 Sep 2026 | Jurojin Poker publishes its statement; IntuitiveTables also confirms it was compromised |
| 29 Sep 2026 | Researcher @wolfsec0x0 goes public on X, saying about 30 high-stakes players were hit |
| Last week of Sep 2026 | Affected players begin finding and disabling the agent |
| June 2026 | Last month a tampered Jurojin update was served |
| June 2025 | Tampered Jurojin updates start reaching one targeted group of users |
| 16 Mar 2024 | Earliest confirmed activity of the remote-access agent, per the researcher |
The agent was built on MeshCentral, a legitimate open-source remote-management program. It installed as a hidden Windows service named “Mesh Agent”. Whoever ran it could see hole cards in real time and reach saved passwords, session cookies and payment cards on the PC.
GGPoker and ClubWPT Gold were named by the researcher as not involved. The poker sites themselves were not breached.
What Jurojin Poker Said
Jurojin calls it a hand-run, highly targeted operation by a known cheater, not a mass hack. Jurojin is an all-in-one multitabling tool that handles table layouts, hotkeys, bet sizing and on-table overlays.
Key points from the statement, in summary:
• How it worked: the attacker intermittently replaced the update package sent to one specific group of users. Some of those packages carried a remote-access tool.
• Who was behind it: a known cheater aiming mostly at high-stakes opponents, to see their hole cards. The same actor also hit IntuitiveTables and ran phishing sites posing as poker rooms and poker tools.
• What stopped it: frequent key rotation, started before the attack was found, left the attacker unable to push further uploads.
• New safeguards: tighter access to sensitive configuration, logging of every server download, and multi-factor authentication wherever server data is edited or deleted.
• Evidence: Jurojin says it has logs of every compromised version and the dates each was served, and has shared reports with authorities and security teams.
• Victims: affected users were contacted privately by email. Jurojin is working with the researcher and apologised to its customers.
No player or suspect has been officially named. Names circulating on social media remain unconfirmed.
Who Is Affected: The Numbers So Far
Roughly 10 to 30 high-stakes players were hit, but the full financial damage is still unknown.
| Measure | Latest figure (as of 1 Oct 2026) |
| Players targeted | About 30 known (researcher range: 10–30) |
| Compromised tools confirmed | 2 (Jurojin Poker, IntuitiveTables) |
| Jurojin exposure window | June 2025 – June 2026 (about 12 months) |
| Earliest agent activity | 16 March 2024 |
| Longest known infection | More than a year on some PCs |
| Poker sites breached | 0 reported |
| Total money lost | Not yet disclosed |
| Official arrests or bans | None announced |
The risk goes beyond poker. Infected PCs exposed saved browser passwords, logged-in sessions and stored cards. The attacker was also seen removing the agent remotely, so some victims may still not know.
How This Compares With Past Poker Superuser Scandals
This is the first major superuser case delivered through third-party software rather than a poker site. Earlier cases came from insiders or a flaw in a site’s own client.
| Year | Case | How cards were seen | Outcome |
| 2026 | Jurojin / IntuitiveTables attack | Malware hidden in tool updates watched players’ screens | Under investigation; reports shared with authorities |
| 2023 | GGPoker “MoneyTaker69” | Modified game client exploited a site vulnerability | Account banned; about $29,795 confiscated and refunded |
| 2007–08 | Absolute Poker “POTRIPPER” and Ultimate Bet | Insider “god mode” access to hole cards | Players cheated out of millions |
The pattern repeats: players and independent researchers, not operators, spotted the cheating first. What is new is the attack surface. HUDs, table managers and other helper tools run with deep access to a player’s PC, which makes them a valuable target.
How to Protect Your Online Poker Account
If you run any third-party poker software on Windows, check your PC today. The steps below follow the checks published by the researcher and PokerStrategy.
1. Look for “Mesh Agent” or “MeshCentral”. Open Services and Installed apps, or run the read-only PowerShell checks in the PokerStrategy guide. Traces can remain even if the attacker removed the agent.
2. Check Windows Security exclusions. If C:\Windows is excluded and you did not add it, treat the PC as compromised.
3. If you find it, disconnect first. Unplug the internet but keep the evidence for police and poker sites.
4. Change passwords from a clean device. Start with your email, then poker, banking and crypto accounts.
5. Log out of all sessions and turn on 2FA. Stolen session cookies can bypass a new password until sessions end.
6. Replace saved cards and move crypto. Ask your bank for new cards; move funds to a wallet set up on a clean device.
7. Report it. Tell every poker site you play on and your local cybercrime authority (in India, cybercrime.gov.in or helpline 1930).
8. Reinstall Windows. Removing the agent alone is not enough.
Going forward, download tools only from official sites, avoid links posing as poker rooms, and keep your poker PC separate from banking and crypto where possible.
Conclusion
The Jurojin statement confirms that online poker’s newest superuser threat came through the side door. No poker site was breached, yet a single attacker could see opponents’ cards for months by poisoning the tools players trust.
The open questions now are how much money was taken, whether poker sites will refund victims, and whether the attacker will be named or charged. Check your PC, lock down your accounts, and bookmark this page for updates.
FAQs
What is the 2026 online poker cyber attack?
A targeted campaign that planted a hidden remote-access agent on high-stakes players’ PCs through tampered updates of poker tools, letting the attacker see their hole cards.
Was Jurojin Poker hacked?
Yes. Jurojin says tampered updates reached one specific group of users between June 2025 and June 2026. It says current versions are clean.
Is Jurojin Poker safe to use now?
Jurojin and the researcher say no current version serves malicious code. Update from the official site and run the checks above.
Which other software was affected?
\IntuitiveTables has confirmed it was also compromised by the same actor.
Were GGPoker or other poker sites hacked?
No. The researcher said GGPoker and ClubWPT Gold were not involved, and no poker site breach has been reported.
How many players were affected?
About 30 high-stakes players are known to have been targeted.

Founder of PokerClubGames.com and a Poker Researcher with 10+ years of experience in SEO, WordPress development, and gaming content strategy. Specializes in researching online poker sites, poker apps, tournaments, bonuses, and poker strategies. Experienced in poker platform reviews, affiliate marketing, and creating SEO-focused poker content for global audiences.
For collaborations, media inquiries, or poker-related partnerships:
Contact: Info@hugecount.com


