Paul Gregg Named in Alleged Poker Superuser Malware Scheme

Reports link a CoinPoker account registered in the Canadian player’s name to a targeted remote-access operation, while Jurojin says only a handful of players had hole cards exposed.
Paul Gregg Named in Alleged Poker Superuser Malware Scheme
October 05, 2026

Canadian high-stakes player Paul Gregg has been named in industry reports as the suspected beneficiary of a remote-access malware operation that allegedly exposed opponents’ hole cards during real-money online poker games. The allegations have not resulted in criminal charges, and the reports cited did not include a response from Gregg.

The suspected operation used compromised versions of the poker utilities Jurojin and IntuitiveTables to install a hidden remote-access agent on selected Windows computers. That access could allow an operator to watch a victim’s screen in real time, control the mouse and keyboard, run commands with system privileges and transfer files, according to CardPlayer.

As we reported Oct. 1, the compromised poker tools gave their controller remote access to affected players’ screens without evidence that poker-site clients themselves had been breached.

WolfSec0×0, a self-described cybersecurity professional, warned players on Sept. 29 of a covert agent planted through compromised poker software. Estimates of the affected group range from 10 to about 30 players or computers across Europe, North America and Oceania, with the operation described as focused chiefly on high-stakes regulars.

Jurojin’s security notice said the attacker selectively swapped update packages for a specific group of users between June 2025 and January 2026. Some, but not all, altered packages carried the remote-access tool, and receiving a tampered package did not necessarily mean a device was infected.

The company said only a handful of high-stakes players suffered in-game exposure of their hole cards, while most users affected by tampered software did not. It said the last uploaded version was not infected, no further material was uploaded after Jan. 28, and it had shared logs and findings with cybersecurity, anti-fraud and law-enforcement authorities.

The allegations against Gregg emerged after the malware warning circulated. PokerStrategy reported that CoinPoker identified an account called Europe, registered in Gregg’s name, as having impossible win rates in less than a week of play. The site banned the account, confiscated $100,000 and redistributed the funds to affected players.

Patrick Leonard said CoinPoker detected the account because it appeared to have more information than its opponents. He also said roughly 100 regular players had raised concerns about it years earlier, although the account allegedly continued to play, win and withdraw funds at implausible rates.

Players have cited unusually strong results as part of the case for further investigation. Patrick Howard submitted 32,780 hands to GGPoker and reported a 13.9-big-blind-per-100-hands win rate and victories in 75.6% of river showdowns for the account he examined. Separately, Ignacio Morón estimated losses of between $100,000 and $200,000 against the suspected account, including about $60,000 in a 15-minute session.

Jurojin said it has begun recording every download, strengthened administrative audit trails, restricted access to sensitive configurations and required multiple authentication factors for key server actions. ACR Poker has also introduced Screen Shield, a tool designed to prevent its tables from being viewed by screen-capture and screen-sharing software.