Poker Sites Warned Over Link to Online Poker Cheating Scandal

The online poker security scandal surrounding the suspected account “Paul Gregg” has taken a new turn, with reports showing that poker operators were warned about the account before the wider investigation emerged. Poker Malware Attack Targeted High-Stakes Players’ Computers The account was linked…
The online poker security scandal surrounding the suspected account “Paul Gregg” has taken a new turn, with reports showing that poker operators were warned about the account before the wider investigation emerged. Poker Malware Attack Targeted High-Stakes Players’ Computers The account was linked to an alleged cyberattack that allowed a suspected cheater to access the computers of high-stakes poker players. The operation allegedly used malware embedded in updates to third-party poker software. Jurojin Poker confirmed its software was one of the affected products. The attackers were able to push altered updates to some users between June 2025 and January 2026, the company said. Another poker management tool, IntuitiveTables, was also said to have been compromised. Players use the software to play multiple tables and automate some of the functions while playing online. The malware reportedly leveraged MeshCentral, a legitimate remote-access system. Once installed, it could allow an attacker to see a player’s screen and control the computer. This access could expose private player cards during live hands. In his investigation of the incident, cybersecurity researcher WolfSec0x0 found 10 to 30 possibly affected computers in several regions. The suspected attack was very selective, not directed against poker players in general. The attacker seemed to have been aiming at particular high-stakes players, Jurojin said, and had previously hit poker-related services. Poker Players Raised Concerns Over Paul Gregg Account Before Scandal The investigation has also cast doubt on the Paul Gregg account. Multiple players reported seeing unusual activity with the account, which led to the details of the malware operation being released. Poker coach Patrick Howard sent an analysis to GGPoker in September, which pointed out the strange patterns associated with the account. He asked the operator to check the activity but did not specifically accuse the account holder of cheating. Later, GGPoker confirmed they had been in contact with Howard regarding their investigation. The same identity has also been the subject of action by another poker operator against an account. CoinPoker reportedly noticed suspicious activity, deleted the account, and seized more than $100,000. Players who participated in the activity were reimbursed afterward. CoinPoker ambassador Patrick Leonard said the account had been on the platform for less than a week before it was noticed. He also said that a bigger group of players had complained about the account to poker operators in past years. Spanish professional Ignacio Morón calculates he lost between $100,000 and $200,000 to the alleged account. He also reported losing roughly $60,000 in a single 15-minute period. The revelations have prompted tighter security measures elsewhere in the industry. ACR Poker has rolled out a feature that blocks screen-sharing and screen-capture software from displaying its poker tables. The incident has been compared to past online poker scandals, including the Potripper case at Absolute Poker and the UltimateBet cheating scheme involving Russ Hamilton. These cases also included access to opponents’ hidden cards and caused great damage to player trust.