A year long campaign that let a hacker peek at the hole cards of some of online poker’s biggest players has finally come to light, after Jurojin, the company behind two widely used table management tools, confirmed that its software update system had been quietly compromised. The Jurojin cyber attack targeted roughly 30 high stakes players through tampered versions of its Jurojin Poker and IntuitiveTables applications, and the company’s public statement this week lays out one of the more sophisticated software based cheating operations the online game has seen in years.
How the Attack Worked
According to Jurojin, the operation ran from June 2025 through June 2026, with the final compromised software version pushed out in June 2026 before the breach was discovered and shut down. Rather than attempting a broad, indiscriminate attack on its entire user base, the attacker selectively replaced update packages distributed to a specific group of high stakes players with tampered versions carrying hidden remote access tools. Once installed, those tools reportedly gave the attacker the ability to view a victim’s hole cards in real time during live play, turning what should have been a routine software update into a direct window into some of the highest value cash games and tournaments on the internet.
Jurojin was blunt about the nature of the campaign in its statement, describing it as “a highly targeted operation, not a mass attack,” and attributing it to “a known cheater aiming at specific opponents, mostly at high stakes.” The company added that the intrusion was “always a selective attack on that specific group of players, carried out by hand by the actor, not a mass or automated blast,” language that suggests investigators believe a single individual, rather than an organized group, was behind the breach.
What Jurojin Is and Why It Matters
Jurojin Poker is not a poker client itself but a productivity layer that runs alongside one, bundling table management, hotkeys, bet sizing shortcuts and real time overlays into a single piece of software that high volume players use to manage several tables at once. Tools like it have become close to essential for serious online grinders, which is precisely what made the attack so effective: because the software runs with elevated access alongside a player’s poker client, a compromised update had a direct line to exactly the information an attacker would want. The second affected application, IntuitiveTables, serves a similar table management function, and both were used as delivery vehicles for the tampered packages.
Beyond the compromised software itself, Jurojin’s statement noted that the same actor also ran phishing sites designed to impersonate legitimate poker rooms and poker tools, widening the potential net of victims beyond just those who downloaded a tampered update directly. That combination, a supply chain compromise paired with phishing infrastructure, points to a patient, resourceful operator who was willing to invest significant time building multiple avenues into the pockets of specific targets rather than looking for a quick score.
Discovery and Jurojin’s Response
The breach came to light thanks to a cybersecurity researcher known as “Wolf,” who is credited in Jurojin’s statement with exposing the attack. Notably, the company says it had already rotated its encryption keys before the breach was discovered, a routine security measure that appears to have limited how much additional damage the attacker could do once the intrusion came to light, and likely forced the operation into the open faster than the attacker intended.
Since confirming the breach, Jurojin says it has restricted access to sensitive configuration systems, begun logging every server side download of its software, and added multiple layers of authentication required before any data altering changes can be made to its systems. The company also says it is maintaining detailed records of the incident for authorities and third party security teams who are now looking into the case, and it privately notified all roughly 30 affected users by email rather than waiting for the broader public statement to inform them.
A Familiar Nightmare for Online Poker
For an industry that has weathered more than one superuser style scandal over the years, news of hole cards being leaked in real time taps directly into online poker’s oldest fear: that the integrity of the game itself, not just a single tournament result, is at risk. Even a narrowly targeted campaign aimed at a few dozen players is enough to rattle confidence among the broader high stakes community, where reputations and bankrolls are built on the assumption that no one at the table has an unfair edge beyond pure skill. Jurojin’s emphasis on the “targeted, not mass” nature of the breach is clearly meant to reassure the wider userbase that casual and recreational players were never the intended targets, but it does little to soften the blow for the specific players whose games were compromised, some of whom may have been facing an opponent who could see their cards for an extended stretch without ever knowing it.
What Comes Next
Jurojin’s statement signals that the matter is now in the hands of outside investigators, and further details, including whether any affected players can identify specific hands or sessions where they were exploited, are likely to surface as that process continues. In the meantime, the episode is a reminder for serious online players that the software running quietly in the background alongside a poker client carries its own security risk, one that is just as real as anything happening at the table itself. Players looking to sharpen their own game while the industry absorbs this news can start with fundamentals that no software vulnerability can take away, such as Poker Pro Academy’s poker hand rankings guidea reminder that skill at the table remains the one edge that cannot be hacked.
Online poker operators and software providers alike will be watching closely to see whether this case prompts broader industry wide audits of third party tools, many of which occupy a similar trusted, high access position on players’ machines. For now, the clearest lesson from the Jurojin breach is one about digital hygiene as much as poker strategy, and a reminder that the games people trust with their bankrolls deserve the same scrutiny as the hands they play.
