Poker Sites Were Warned Before Online Cheating Scandal Emerged

United States.- 7 October 2026 | www.zonadeazar.com New details surrounding the recent online poker security scandal indicate that several poker rooms had received warnings about a suspicious account before the wider scope of the case became public.

The investigation centres on an identity known as “Paul Gregg”, linked to an alleged attack targeting high-stakes players through compromised third-party poker software.

Malware in Third-Party Software

The attack is not believed to have directly compromised poker-room clients.

Instead, those responsible allegedly used altered versions of external tools commonly used by professional players to manage multiple tables and automate certain functions.

Affected products included:

  • Jurojin Poker.
  • IntuitiveTables.

Remote Access to Players’ Computers

The malware reportedly used a legitimate remote-management tool to access selected players’ computers.

Once installed, it could allow an attacker to view a player’s screen and control the device.

This could expose private hole cards while hands were still being played.

High-Stakes Players Targeted

The operation does not appear to have been indiscriminate.

Jurojin said the attacker specifically targeted high-stakes players.

Initial investigations identified between 10 and 30 potentially affected computers across several regions.

The “Paul Gregg” Account

One of the identities linked to the case used the name “Paul Gregg”.

Several players began identifying unusual statistical patterns and decisions associated with the account during high-stakes games.

Those reports later helped connect the suspicious activity with the wider cybersecurity incident.

GGPoker Had Received a Report

Poker coach Patrick Howard sent GGPoker an analysis in September highlighting unusual patterns associated with the account.

Howard did not directly accuse the player of cheating.

Instead, he asked the operator to investigate the activity more closely.

GGPoker later confirmed it had been in contact with Howard regarding the investigation.

CoinPoker Took Action

CoinPoker also identified suspicious activity involving an account associated with the same identity.

According to published accounts, the platform:

  • Banned the account.
  • Confiscated more than $100,000.
  • Refunded affected players.

Site ambassadors said the account had been active for less than a week before it was detected.

Earlier Player Warnings

Patrick Leonard said a group of around 100 regular players had raised concerns about the account with different operators over a period of years.

According to his account, the identity was still able to continue playing and withdrawing money on some platforms despite those warnings.

These statements remain player testimony rather than a judicial finding.

Six-Figure Losses

Spanish professional Ignacio Morón estimates that he lost between $100,000 and $200,000 against the account under investigation.

He has also said he lost approximately $60,000 in a single 15-minute period.

The figures form part of the reconstruction provided by affected players.

ACR Poker Strengthens Security

The scandal has already prompted changes to platform security.

ACR Poker introduced a feature preventing screen-capture and screen-sharing software from displaying its poker tables.

The measure is intended to reduce the risk of third-party tools being used to view players’ private cards during live hands.

Online Poker Trust

The incident has revived concerns around so-called “superuser” scandals.

Past cases demonstrated how unauthorised access to hidden cards can severely undermine player confidence.

The key difference in this case is that the alleged attack vector was third-party software installed on victims’ own computers.

Next Steps or Impact

The investigation continues to determine the full scale of the attack, the number of players affected and which accounts may have benefited from compromised information.

The case increases pressure on poker operators to share information on suspicious behaviour and strengthen oversight of third-party software used by their customers.

It may also accelerate adoption of measures designed to prevent screen capture, remote access and other tools capable of compromising the integrity of online games.

Editó: @fonta

Compartir: