Online Poker Cyber Attack: Third-Party Software Provider Responds

Last Updated on October 1, 2026 by Bala Kumar

SEO Setup

FieldValue
SEO titleOnline Poker Cyber Attack: Jurojin Explains the Hack (2026)
Meta descriptionJurojin Poker confirms a year-long targeted attack let a cheater view high-stakes players’ hole cards. What happened, who was hit, and how to stay safe.
URL slug/online-poker-cyber-attack-jurojin-statement
Focus keywordonline poker cyber attack
Secondary keywordsJurojin Poker hack, online poker superuser scandal, poker cheating 2026, IntuitiveTables, hole cards exposed, poker software security
Long-tail keywordsis Jurojin Poker safe to use, how did hackers see poker hole cards, poker HUD malware, how to protect online poker account

Use the focus keyword in the H1, the first 100 words, one H2 and the image alt text. Keep density near 1%.

Introduction

The biggest online poker cyber attack in years did not break into a poker site. It came through the tools players trust to run beside their tables.

On 30 September 2026, Jurojin Poker confirmed that an attacker had secretly swapped its software updates for a small group of users between June 2025 and June 2026. Some of those tampered updates carried a remote-access tool that let the attacker watch victims’ screens, including their hole cards. About 30 high-stakes players are known to have been targeted.

Here is what happened, what Jurojin says it has fixed, and what every online poker player should do now.

What Happened in the Online Poker Cyber Attack

The attack hijacked trusted poker tools, not poker sites. An attacker slipped a hidden remote-access agent onto players’ Windows PCs through tampered updates of third-party table-management software, then watched their screens live.

DateEvent
30 Sep 2026Jurojin Poker publishes its statement; IntuitiveTables also confirms it was compromised
29 Sep 2026Researcher @wolfsec0x0 goes public on X, saying about 30 high-stakes players were hit
Last week of Sep 2026Affected players begin finding and disabling the agent
June 2026Last month a tampered Jurojin update was served
June 2025Tampered Jurojin updates start reaching one targeted group of users
16 Mar 2024Earliest confirmed activity of the remote-access agent, per the researcher

The agent was built on MeshCentral, a legitimate open-source remote-management program. It installed as a hidden Windows service named “Mesh Agent”. Whoever ran it could see hole cards in real time and reach saved passwords, session cookies and payment cards on the PC.

GGPoker and ClubWPT Gold were named by the researcher as not involved. The poker sites themselves were not breached.

What Jurojin Poker Said

Jurojin calls it a hand-run, highly targeted operation by a known cheater, not a mass hack. Jurojin is an all-in-one multitabling tool that handles table layouts, hotkeys, bet sizing and on-table overlays.

Key points from the statement, in summary:

•           How it worked: the attacker intermittently replaced the update package sent to one specific group of users. Some of those packages carried a remote-access tool.

•           Who was behind it: a known cheater aiming mostly at high-stakes opponents, to see their hole cards. The same actor also hit IntuitiveTables and ran phishing sites posing as poker rooms and poker tools.

•           What stopped it: frequent key rotation, started before the attack was found, left the attacker unable to push further uploads.

•           New safeguards: tighter access to sensitive configuration, logging of every server download, and multi-factor authentication wherever server data is edited or deleted.

•           Evidence: Jurojin says it has logs of every compromised version and the dates each was served, and has shared reports with authorities and security teams.

•           Victims: affected users were contacted privately by email. Jurojin is working with the researcher and apologised to its customers.

No player or suspect has been officially named. Names circulating on social media remain unconfirmed.

Who Is Affected: The Numbers So Far

Roughly 10 to 30 high-stakes players were hit, but the full financial damage is still unknown.

MeasureLatest figure (as of 1 Oct 2026)
Players targetedAbout 30 known (researcher range: 10–30)
Compromised tools confirmed2 (Jurojin Poker, IntuitiveTables)
Jurojin exposure windowJune 2025 – June 2026 (about 12 months)
Earliest agent activity16 March 2024
Longest known infectionMore than a year on some PCs
Poker sites breached0 reported
Total money lostNot yet disclosed
Official arrests or bansNone announced

The risk goes beyond poker. Infected PCs exposed saved browser passwords, logged-in sessions and stored cards. The attacker was also seen removing the agent remotely, so some victims may still not know.

How This Compares With Past Poker Superuser Scandals

This is the first major superuser case delivered through third-party software rather than a poker site. Earlier cases came from insiders or a flaw in a site’s own client.

YearCaseHow cards were seenOutcome
2026Jurojin / IntuitiveTables attackMalware hidden in tool updates watched players’ screensUnder investigation; reports shared with authorities
2023GGPoker “MoneyTaker69”Modified game client exploited a site vulnerabilityAccount banned; about $29,795 confiscated and refunded
2007–08Absolute Poker “POTRIPPER” and Ultimate BetInsider “god mode” access to hole cardsPlayers cheated out of millions

The pattern repeats: players and independent researchers, not operators, spotted the cheating first. What is new is the attack surface. HUDs, table managers and other helper tools run with deep access to a player’s PC, which makes them a valuable target.

How to Protect Your Online Poker Account

If you run any third-party poker software on Windows, check your PC today. The steps below follow the checks published by the researcher and PokerStrategy.

1.         Look for “Mesh Agent” or “MeshCentral”. Open Services and Installed apps, or run the read-only PowerShell checks in the PokerStrategy guide. Traces can remain even if the attacker removed the agent.

2.         Check Windows Security exclusions. If C:\Windows is excluded and you did not add it, treat the PC as compromised.

3.         If you find it, disconnect first. Unplug the internet but keep the evidence for police and poker sites.

4.         Change passwords from a clean device. Start with your email, then poker, banking and crypto accounts.

5.         Log out of all sessions and turn on 2FA. Stolen session cookies can bypass a new password until sessions end.

6.         Replace saved cards and move crypto. Ask your bank for new cards; move funds to a wallet set up on a clean device.

7.         Report it. Tell every poker site you play on and your local cybercrime authority (in India, cybercrime.gov.in or helpline 1930).

8.         Reinstall Windows. Removing the agent alone is not enough.

Going forward, download tools only from official sites, avoid links posing as poker rooms, and keep your poker PC separate from banking and crypto where possible.

Conclusion

The Jurojin statement confirms that online poker’s newest superuser threat came through the side door. No poker site was breached, yet a single attacker could see opponents’ cards for months by poisoning the tools players trust.

The open questions now are how much money was taken, whether poker sites will refund victims, and whether the attacker will be named or charged. Check your PC, lock down your accounts, and bookmark this page for updates.

FAQs

What is the 2026 online poker cyber attack?

A targeted campaign that planted a hidden remote-access agent on high-stakes players’ PCs through tampered updates of poker tools, letting the attacker see their hole cards.

Was Jurojin Poker hacked?

Yes. Jurojin says tampered updates reached one specific group of users between June 2025 and June 2026. It says current versions are clean.

Is Jurojin Poker safe to use now?

Jurojin and the researcher say no current version serves malicious code. Update from the official site and run the checks above.

Which other software was affected?

\IntuitiveTables has confirmed it was also compromised by the same actor.

Were GGPoker or other poker sites hacked?

No. The researcher said GGPoker and ClubWPT Gold were not involved, and no poker site breach has been reported.

How many players were affected?

About 30 high-stakes players are known to have been targeted.

Leave a Reply

Your email address will not be published. Required fields are marked *

Poker Platform

Suprema Poker review covering its app features, games, ratings, updates, club-agent model, security, real-money risks, and India availability.

 
 

Bravo Poker Live review 2026: explore live poker games, waitlists, tournament clocks, features, ratings, and room coverage.

 
 
1Win Poker review 2026 covering bonuses, games, payments, mobile apps, licensing, and withdrawals.
Explore RedStar Poker’s $2,000 welcome bonus, up to 35% rakeback, iPoker games, traffic, software, and payment options in 2026.

Explore BetRivers Poker’s $1,000 bonus, low rake, multi-state games, app features, and payment options in 2026.

Explore BetMGM Poker’s $1,000 bonus, soft games, MGM Rewards, mobile app, tournaments, and payment options in 2026.