Start Grinding for FREE!
Security Notice: Update Package Incident (June 2025 – June 2026)

We want to share what happened, what we've done about it, and what you should do if you were affected.
What Happened
We want to thank Wolf. This came to light through a closed high-stakes group on Discord. This week, our investigation found that between June 2025 and June 2026, an attacker was able to intermittently replace the update package delivered to one specific group of Jurojin users with a tampered version. June 2026 was the last compromised month. Some of those packages included a remote-access tool.
This was a highly targeted operation, not a mass attack. It was carried out by a known cheater aiming at specific opponents, mostly at high stakes, with the goal of viewing their hole cards remotely. Jurojin was one of several applications targeted by the same actor, including IntuitiveTables. The same actor also operated phishing sites impersonating poker rooms and well-known poker tools.
Who Was Affected
Our records identify a limited group of accounts that may have been served a tampered update during that period. Not all tampered packages contained the remote-access tool, and exposure does not mean a device was infected. As a precaution, we have contacted every one of these users privately by email from support@jurojinpoker.com.
If you did not receive an email from us, our records show your installation did not receive the tampered package.
What We've Done
Nothing else was uploaded to our servers after January 28, 2026. Our policy of rotating keys frequently, and our other security measures, left the attacker unable to upload anything further. We have logs of every compromised version and the dates it was served, for authorities and security teams.
We had already been strengthening security even before we learned of any compromised security. Before we understood this specific attack, we had rotated all server access keys, tightened permissions, and rotated the encryption keys used between the app and our servers. In retrospect, those changes helped mitigate the attacks even though we did not yet know about them.
Once we had the full picture this week, we went further:
Every download from our servers is now logged.
Administrative actions have stronger audit trails.
Access to sensitive configuration has been further restricted.
Key places where data is edited or deleted on our servers now require multiple authentication factors.
Amazon Web Services support was contacted for more logs.
We are in contact with investigators and security teams to gather data.
We are working with poker room security teams and with Wolf, the independent cybersecurity expert leading the investigation.
What You Should Do
If you received our email, if you saw something suspicious on your PC, if it has been running slower than usual, if you feel someone has been playing against you and always winning, or you notice similar signs: we recommend a clean Windows reinstall from scratch (format to zero). That is the best way to be sure the PC is safe.
If you decide not to reformat, you can check your PC with Jurojin Mesh Check. A clean result is not a guarantee:
Always run the latest version of Jurojin, downloaded only from jurojinpoker.com.
Keep your antivirus up to date, and leave Windows Defender turned on.
Please stay alert to impersonation. We will never ask for your passwords and we will never send you attachments. The only official check tool is the one on jurojinpoker.com.
Indicators of Compromise
For security teams, other poker tools and technical users. Do not visit these addresses.
The same server hosted phishing sites impersonating poker rooms, casinos and poker apps. Players who use any of these could be targeted:
Casinos and poker rooms: Bodog, Ignition, ACR Poker, GGPoker, PokerKing, Winning Poker Network, BCPoker.
Apps and tools: Hand2Note, IntuitiveTables, fake casino domains, and similar apps or sites are or could be compromised.
Phishing Domains
okayvpn[.]org www-bodog[.]eu acr-poker[.]eu www.acr-poker[.]eu xn--winningpokernetwork-h0c[.]com xn--posolver-tkb[.]com www.xn--posolver-tkb[.]com netverify[.]org www.netverify[.]org ignitioncasino[.]cc www.ignitioncasino[.]cc ignitioncasino[.]email www.ignitioncasino[.]email winningpoker[.]network www.winningpoker[.]network ggnetwork[.]org www.ggnetwork[.]org pokerking[.]email intl.pokerking[.]email acrtabletalker[.]com www.acrtabletalker[.]com hand2note[.]org www.hand2note[.]org winningpokernetwork[.]com bcpoker[.]eu gtosoftware[.]com wpnpoker[.]com
How It Worked
The attacker swapped the update package served to specific users. Some of those packages included a remote-access tool.
We were able to corroborate every historical version of the software that was served, and which of those versions were malicious and which were not. It was always a selective attack on that specific group of players, carried out by hand by the actor, not a mass or automated blast.
We have extensive reports of our findings for authorities and security teams who are interested. Some of them already have those reports.
Our Commitment
We're sorry. Our users trust us with software that runs on their computers, and that trust was abused.
Security remains a priority for us despite this specific case. The improvements we made throughout the year show that. Stronger authentication, rotated keys, and the other changes we put in place left the attacker unable to continue the scheme, even though we did not yet know about it. That was a side effect of work we had already done.
We still suffered the attack. For the future, we will be better prepared. We will keep this page updated as the investigation progresses. For any questions, reach us at support@jurojinpoker.com.
Thank you again to Wolf and to everyone who got involved in gathering as much information as possible and in talking through this incident with us. We remain actively attentive to new attacks or discoveries.
— The Jurojin team