
In the wake of a superuser scandal that targeted a group of high-stakes players, Jurojin Poker, one of two compromised software products, is taking steps to prevent future attacks and maintain the integrity of online poker.
Last week, cybersecurity expert @wolfsec0x0 exposed an online poker cheating scandal that involved attackers using third-party software to gain access to an online poker player’s screen. One high-stakes player, Ignacio Moron, believes he was cheated out of at least $100,000.
Jurojin Poker, which previously released a statement addressing the situation, answered PokerNews‘ questions about the attack, including how they were alerted to it, who was effected, and what steps they are taking to prevent future attacks.
Jurojin Poker Talks About Superuser Attack
PokerNews: When did this cyber attack first come to Jurojin Poker’s attention?
Jurojin Poker: We found out the same way the community did. Wolf’s investigation, together with suspicions raised by high-stakes players, brought this to light, and we learned about it as the public story unfolded. For a long time we had been fighting crackers who sold pirated copies of Jurojin at very low prices, so some of the unusual activity we saw along the way got lumped in with that. We assumed it was the same kind of problem, not a targeted attack on our users.
Jurojin Poker says this was a highly targeted attack. Can you say who was affected and who wasn’t?
We don’t have much to add beyond what others have already shared. The attack was aimed mainly at high-stakes players, to a lesser extent at mid-stakes, and to a much lesser extent at low-stakes. On Jurojin’s side, the infections were passive: the tampered update infected the PC and installed the spyware (Mesh) on more machines than the attacker later actually used to snipe hands.
We have a list of users we can confirm were in the affected version groups at specific dates and times, and we are notifying them directly. We cannot say that list is complete. The attacker covered his tracks by moving people between groups and quickly pulling them out, and continuous backups of a database this large are not feasible, since they would overload any server. So there may be affected users we cannot identify. If you received an update from us during the period in question, please follow the steps in our answer to the next question.

This mainly targeted high-stakes players. Do low-stakes players have anything to worry about?
We have no evidence that low-stakes players were targeted for sniping, so there is little reason to worry about someone looking at your cards while you play. But that doesn’t rule out having been infected with Mesh, or still being infected. Our general recommendation is to wipe and reinstall your PC from scratch, so you can be completely at ease. We understand this can be very inconvenient, even though a clean reinstall is good security hygiene to do twice a year anyway. If you’d rather not do that, please at least run our tool to check whether Mesh is still installed on your PC.
Can Jurojin Poker provide an update on its work with “Wolf” (who discovered this cyber attack) and the measures being taken to prevent future attacks?
Wolf deserves all of the credit. He discovered the attack and has led the investigation from the start. Our role has been to support it: we did reporting and assessment on top of what he found to add information, and we have detailed reports ready to share with him and with casino security teams.

We have taken several measures, which are published in our security notice. We have also already deployed new code-level improvements. We removed the periodic saving of hands that we used to diagnose connection stability with the room, leaving only manual hand saving when you send us a report. This minimizes the playing-style data stored on your PC, even though it was already very little. We also added internal security validations to prevent similar attacks in our supply chain.
“Wolf deserves all of the credit. He discovered the attack and has led the investigation from the start.”
We have filed reports with international authorities in the jurisdictions where we understand the attacker was operating.
Has Jurojin Poker come across any other suspicious accounts or users other than “Paul Gregg”?
We had suspicions about a few accounts, but nothing we could confirm that was solid enough to be worth mentioning. We also don’t do any game data analysis, so we can’t raise suspicions based on playing style. That is exclusively the casinos’ responsibility, since they are the ones who can see all the hands.
It’s also part of what really happened: we had been fighting crackers who sold pirated versions of Jurojin and taking many security measures against them. Along the way, some of the attacks that were actually this attacker’s were mistakenly attributed by us to those crackers.
Superuser Scandal: Poker Sites Were Warned About Suspicious Account
What is Jurojin Poker’s message to those in the poker community who are concerned about online poker integrity?
We take what happened extremely seriously, and we understand why people are concerned.
That said, online poker has always faced stories claiming it was dying, and the reality is that it isn’t. Many of us think this is pure sensationalism. There is still a lot of volume, and people in every area of life are more and more comfortable with the virtual world, especially since COVID. I see no reason to think one piece of bad news could bring down an entire segment of an industry this big.

A video calling this the biggest story in online poker history, and saying it means the end of online poker, is far catchier than saying what actually happened: computers were infected so the attacker could play against high-stakes players while seeing their cards. However much money he made, it was still a targeted attack, and it happened at a time when our own security was weaker than it is today, and we have strengthened it since.
Our position is, of course, that we would love for the affected users to get their funds back, and we believe the casinos have a major responsibility to make that happen.
To anyone who is worried, I invite you to look at the player pools at each casino. Plenty of tournaments, cash tables and spins run every day, at all hours. I can’t think of a better answer than that, so please don’t be carried away by sensationalism.
To everyone who was affected, we are truly sorry. We take security very seriously and always have; it’s something we are passionate about. We are constantly watching talks and videos and consulting people who know more than we do in order to improve it. The attack was a blow to our ego, but it also gave us some optimism: the security measures we had been putting in place over the last few months worked, and the attacker was kept out. It also left us with more tools to see exactly what happened, to learn from it, and to make any future attack much harder.

