
PokerNews reports sites were warned about the Paul Gregg superuser account before public exposure. One banned it and seized $100,000; players lost up to $200,000 each. The targeted hole-card viewing software hit around 30 high-stakes victims.
SCCG Take — Operators face immediate pressure to convert player warnings into account bans and refunds. Delayed action on anomalous win rates invites both reputational damage and renewed regulatory scrutiny of platform integrity controls.
Online poker sites received warnings about a suspicious account before a cybersecurity expert exposed a superuser scandal. The account named Paul Gregg allegedly used third-party software to view opponents’ hole cards. It targeted around 30 high-stakes players and cost victims six figures.
The exposure began when X user and cybersecurity expert @wolfsec0x0 detailed the two-year-old breach. According to reporting by PokerNews, poker coach Patrick Howard submitted a report to GGPoker in September about unusual behavior from the Paul Gregg account. Howard, who has said the scandal “will change online poker forever,” later wrote on X that GGPoker had reached out about the investigation.
One site banned the Paul Gregg account more than two years ago after its security team detected the superuser activity. High-stakes player Mario Mosbock, an ambassador for the unregulated site, confirmed the platform confiscated $100,000 before issuing the ban. Poker pro Ignacio Moron estimates he lost between $100,000 and $200,000 to the account, including $60,000 in 15 minutes.
Prominent online pro Patrick Leonard, also a site ambassador, wrote on X that the account was caught “around 1 year ago after he had played less than a week on the site.” Leonard added “we didn’t know exactly what he was doing, but it was obvious he had more information than other players.” He noted a group of around 100 poker players voiced suspicions years ago, but the account continued to play and withdraw at “win rates that were likely not possible and showdowns that didn’t make sense.”
Leonard wrote that “The future of online poker is in the hands of the sites and how much they are willing to investigate and act on bots & standalone characters like this.”
Compromised software provider Jurojin Poker stated “This was a highly targeted operation, not a mass attack.” The statement continued that it was carried out by “a known cheater aiming at specific opponents, mostly at high stakes, with the goal of viewing their hole cards remotely.” Jurojin was one of several applications targeted, including IntuitiveTables. The actor also operated phishing sites impersonating poker rooms.
The incident follows major superuser scandals, including Russ Hamilton’s use of the “POTRIPPER” account to cheat players on Absolute Poker and Ultimate Bet in the late 2000s. It remains unclear how many sites were affected by the software breach.
Reporting: PokerNews
Generated by SCCG’s automated editorial system from published source reporting. SCCG Management holds editorial responsibility.
Gaming, betting and prediction markets — the desk’s read, every weekday.
Subscribe →