A new PokerNews investigation says online poker sites were warned about a suspicious "superuser" account well before the Jurojin software breach became public. The account, named Paul Gregg, allegedly targeted around 30 high-stakes players across several sites. Victims describe heavy losses, and several poker figures say the response from sites was slow. This article lays out what has been reported, what remains unclear and what players can do now.
What PokerNews reported
The piece, published on October 2, 2026, describes a cyber attack in which third-party software, specifically Jurojin Poker and IntuitiveTables, allowed an attacker to view players' hole cards remotely. The fraudulent account "Paul Gregg" allegedly benefited from that information while playing high-stakes games.
Key points from the reporting:
- Suspicious activity was first noticed about two years earlier.
- A group of around 100 poker players had voiced suspicions years before the breach became public.
- One poker site detected and banned the account around a year ago.
- One unregulated site confiscated $100,000 from the account.
- In September 2026, Mobius Poker coach Patrick Howard submitted a warning report to GGPoker, and GGPoker reportedly reached out about the investigation.
We covered the technical side of the story in our Jurojin software hack explainer. This article focuses on the timeline and the question of responsibility.
The human cost
Spanish professional Ignacio Moron told PokerNews he lost between $100,000 and $200,000 in total, including about $60,000 in a single 15-minute session. Those are large numbers even at high stakes, and they hint at how powerful hole-card information is. Knowing an opponent's hand removes most of the uncertainty from poker. Even a small number of sessions can produce massive swings.
Patrick Leonard, a site ambassador, noted that the account "obviously had more information than other players." He also said: "The future of online poker is in the hands of the sites." Jurojin has described the incident as "a highly targeted operation, not a mass attack."
What Jurojin said
According to a PokerFuse summary of Jurojin's statement, the company's update packages were compromised between June 2025 and June 2026. In its words, "an attacker was able to intermittently replace the update package delivered to one specific group of Jurojin users with a tampered version." The tampered versions allegedly included remote-access tools that exposed hole cards. Potentially affected platforms mentioned in the reporting include GGPoker, CoinPoker and WPN. Todd Witteles reported that both Jurojin and IntuitiveTables may have been affected by exploited software packages.
We should be careful. These are reports and statements, not court findings, and the full scope is not public. The sites themselves do not appear to have been breached; the weakness was software running on players' own computers.
The core question: who should have acted?
Poker sites rely on a mix of automated detection and player reports. The superuser story highlights three weaknesses.
1. Detection depends on patterns. An account that seems to know more than it should can be hard to prove from hand histories alone, especially at high stakes where variance is huge. Statistical suspicion is not evidence.
2. Cross-site communication is limited. One site banned the account about a year ago and another confiscated $100,000, but players say there was no coordinated alert. If sites shared intelligence about suspicious accounts, the damage might have been smaller.
3. Third-party software sits in a gray area. Tools like those used by serious grinders to manage tables are often permitted, but sites cannot easily audit them. When a tool's update mechanism is compromised, the site is blind to it.
Howard's warning to GGPoker in September and the earlier suspicions of about 100 players suggest that some people did raise concerns. Whether that information reached decision-makers in time is the heart of the controversy.
How the Paul Gregg account fits the wider integrity picture
Poker integrity stories are not new. Past scandals involving real-time assistance, colluding players and insider access have each led to changes in site policies. Our coverage of AML rules threatening Vegas high-stakes games and the ACR final table replayer hole-card controversy shows that integrity is a constant theme. What is unusual here is the combination of a supply-chain-style software attack and a long-running account that allegedly exploited it.
What players can do now
Whether or not you play high stakes, the risks apply to anyone who installs third-party tools.
- Audit your software. Remove tools you do not actively use. Check the publisher's official channels for security notices. If you used Jurojin or IntuitiveTables, read the vendors' statements carefully.
- Verify updates. Where possible, update only from official sources and confirm file integrity. Be suspicious of unexpected update prompts.
- Scan your machine. Run reputable anti-malware tools, and consider reinstalling your operating system if you suspect compromise.
- Use separate devices. Playing on a dedicated machine with minimal software lowers risk.
- Report concerns. If an opponent seems to know too much, send detailed hand histories to site security. Specific hand numbers and dates help investigators.
- Choose sites with strong security reputations. Our safe poker sites guide explains what to look for, and our poker networks overview compares platforms.
If you prefer crypto-focused rooms, review BC Poker, which advertises provably fair dealing, and our crypto poker guide. Provably fair shuffling addresses a different risk, since it verifies the deck rather than your own device, but it shows the industry's interest in transparency.
What sites should do
The story creates pressure on operators to improve three things: communication, tooling and consequences. Faster internal escalation of player reports, clearer rules for third-party software and published outcomes for confirmed cases would all help rebuild trust. Players also deserve to know whether they were affected. As Leonard put it, the future of online poker is in the hands of the sites.
For regulated markets, scrutiny may be stronger. Regulators can demand incident reports from licensed operators, though the reach is limited for unregulated sites. Our real-money poker guide and US poker page explain how licensing affects player protections.
What this means for players
The practical lesson is that your own computer is part of the security chain. Hole-card exposure did not require a hack of a poker site; it exploited software that players chose to install. Reduce the number of tools you run, keep them updated from verified sources and treat unexplained patterns seriously.
For players who have lost money to a suspected cheater, the options depend on the site and jurisdiction. Contact support, provide hand histories and ask whether the site has opened an investigation. Do not rely on public accusations alone; keep your evidence organized.
Bottom line
The Paul Gregg case shows how a technical vulnerability and slow institutional response can combine into a serious integrity problem. Reported losses of $100,000 to $200,000 for a single victim, about 30 high-stakes targets and a trail of warnings dating back years make this one of the biggest online poker stories of 2026. Many facts are still unconfirmed, and we will update this article as sites and software vendors release more information. In the meantime, protect your machine, verify your tools and demand transparency from the rooms where you play.