ACR Poker Activates Screen Shield After Remote-Access Cheating Allegations

The WPN safeguard blocks table capture and streaming for selected users while ACR reviews affected hand histories in an investigation that could lead to compensation.

ACR Poker and the Winning Poker Network have introduced a new protection called Screen Shield after allegations that high-stakes players’ hole cards were exposed through compromised third-party software. The measure is designed to stop WPN tables from appearing in screen-capture and screen-sharing tools.

WPN contacted players on Sept. 29 whose computers were identified as running remote-access, screen-sharing or screen-control software, and activated Screen Shield for them. Phil Nagy, ACR Poker’s CEO, announced the move in a statement.

The safeguard comes with a clear trade-off. Players cannot take screenshots of winnings or stream on Twitch or Kick while Screen Shield is enabled. WPN said it will scan the network regularly and ask players whether they want the feature activated when it detects screen-sharing software.

ACR said it does not believe its poker-client software was compromised. Instead, the alleged attackers used malicious versions of third-party poker tools to place remote-access software on players’ computers, potentially allowing them to view a target’s live screen while playing.

ACR Poker has sent hand histories from affected players to GTO Wizard for analysis and said its wider investigation could result in compensation. ACR and GTO Wizard already had a partnership covering hand-history cross-checks and tools intended to flag real-time assistance, bots and other suspicious play.

As covered in our Sept. 30 report, the broader allegations centered on a covert remote-access agent installed on Windows PCs through compromised poker software. Cybersecurity researchers estimated that roughly 10 to 30 players had been affected since 2024, with the software capable of displaying hole cards to an attacker and accessing other sensitive information on an infected computer.

The compromised tools identified in the reports were Jurojin Poker and IntuitiveTables. Jurojin said about 30 high-stakes players were known to have been targeted and described the attack as selective rather than a mass campaign. It said an attacker intermittently delivered tampered updates to a specific group between June 2025 and June 2026, including packages containing remote-access software; that timeline differs from PokerOrg’s report that Jurojin said the infection ended in January.

The allegations have also prompted claims about accounts tied to Paul Gregg. CoinPoker banned an account named “Europe,” which it said was registered in Gregg’s name, and issued refunds to affected players. CoinPoker ambassador Patrick Leonard said the site confiscated more than $100,000 from the account, while player Ignacio Morón said CoinPoker refunded him about $60,000.

Nagy said WPN plans to add a future update that lets players turn on Screen Shield themselves, and offered the technology to other poker operators.

21+ in OH. Please play responsibly. For help, call the Ohio Problem Gambling Helpline at 1-800-589-9966 or 1-800-GAMBLER.
published 1 hour, 53 minutes ago • by Team F5 • permalink

Keep Reading:

« Back to Homepage