As reliably as a sunrise, a new cheating scandal has arisen in the online poker world. This time, a player known by various aliases, including 'Paul Gregg,' managed to compromise some third-party poker applications.
This person was then able to see the hole cards of players who had downloaded the compromised applications. PokerOrg has detailed the response from some operators, along with reaction from the player community.
One of the unfortunate features of this particular situation is that apparently one site was aware of the cheater a year or more ago. Why, players have wondered, do sites not share information about cheaters with each other?
One site, one cheater
First, let's clarify what we're talking about. If a player on a specific site is winning far beyond what is statistically reasonable, the site has a responsibility to review their results and look for cheating.
It seems that 'Paul Gregg' (and their aliases) had been reported to various sites by multiple respected high-stakes players.
While a handful of players, by definition, must be at the statistical tail of positive results, there are results that go beyond statistical expectation. For instance, anybody who saw the infamous 'NioNio' win rate graph, compared to that of the best players on Ultimate Bet, would immediately know that something wasn't right.
I don't know if 'Paul Gregg' or their aliases had those kinds of results, but if they did, then the sites needed to do something about it. And in fact, one site did do something about it. A site which has this sort of evidence and doesn't act on it has abdicated its responsibility to its customers.
Sharing cheater information among sites
This is where things get muddier. The bottom line is that sites are very unlikely to share suspected cheater information with each other.
Let's say that online site AlphaPoker discovers that NastyNate is cheating. How they 'know,' or even suspect this, isn't important here. Let's stipulate that they boot Nate from the site. Perhaps they confiscate their funds on deposit, and maybe they distribute those funds to the people NastyNate cheated. Again, none of this is relevant.
The question: Why doesn't AlphaPoker call up online site BetaPoker and say, "Hey, NastyNate is a cheat and you should boot them from your site." After all, because of KYC rules, AlphaPoker knows exactly who NastyNate is, down to their passport number.
In fact, players continue to argue that sites should share information with each other about suspected cheaters. In the article I linked above, well-known pro Patrick 'Pads' Leonard is quoted,
"Every site bans people every day, no site has ever told another site the players they have banned. We did not know what he was doing [and that he had] hacked Jurojin/IntuitiveTables.”
Leonard acknowledges that there's some asymmetry for a site that goes to the trouble of finding and catching cheaters:
"It’s unfair if site x spend infinite $ on security whilst site y spends 0 and then site y basically can just rely on site x. There is so much politics right now between the sites, smear campaigns etc that it’s just not feasible for them to work together.”
The unfortunate social media wars aside, it's true that AlphaPoker doesn't want to act as the unpaid security consultant for BetaPoker. It's in AlphaPoker's interest to see fraudsters and cheaters shoved out of the community altogether, including at BetaPoker. But that interest doesn't rise to a level of a willingness to just hand BetaPoker all their security intel. Especially if BetaPoker isn't reciprocating with intel of their own.
But none of this is the main reason anyway.
General Data Protection Regulation
The elephant in the room here is the General Data Protection Regulation ('GDPR'). The GDPR is an expectedly lengthy document that dictates how companies have to protect the personal information of their EU-based customers.
AlphaPoker can boot NastyNate (and confiscate their funds) just because a security guy within the company says, "I'm pretty sure NastyNate is a cheater." That's within their Terms and Conditions and there's not a damn thing Nate can do about it.
However, the moment they tell BetaPoker they think Nate is a cheater, an entirely different set of rules apply. Telling BetaPoker about Nate is a 'disclosure' under the GDPR. Under Article 6 of the GDPR, AlphaPoker would need sufficient justification for that sharing.
AlphaPoker would have to justify this disclosure and show that its legitimate interests aren't overridden by the rights and freedoms of the person involved. While fraud might well constitute sufficient justification, cheating on a grey market poker site is a violation of what law?
Furthermore, if it turns out that AlphaPoker is wrong, and Nate isn't a cheater, then they can be in deep legal trouble if Nate decides to come after them. Again, they can boot Nate, confiscate their funds, and be dead wrong – Nate has pretty much zero recourse. The moment they involve BetaPoker, if they're wrong, Nate can make their lives miserable.
AlphaPoker is highly motivated to run a tight security ship – that's just good business. When they find somebody who they think is a cheater, the clear +EV play is to get rid of that person. If they're very sure, and that's how they want to run the business, they can confiscate the presumed cheater's funds and distribute them to the cheater's victims.
But in the context of the GDPR, it can't be a good choice for them to share that information with any other site.
What about casinos and sports betting?
In the linked article, Spanish poker pro Ignacio Morón is quoted saying, "If you go to Las Vegas and any casino catches someone cheating, all the casinos know it – they have the picture and if you go into another casino they kick you out too.”
If you cheat a Las Vegas casino, you potentially face arrest and criminal prosecution, not merely an account ban. Unfortunately, cheating at poker rarely ends up with an arrest – grist for a different article.
But the point is that cheating in a Las Vegas casino violates Nevada law. The casinos can track who has been convicted under such laws. They also can, and probably do, share information about such cheaters. This is likely permitted, if not required, under Nevada gaming rules.
The same is true of sports betting. Regulated legal sports betting is a $100-billion industry worldwide. Furthermore, the underlying sports have their own hundreds of billions at stake, which count on the cleanliness of their reputation. They have ample legislative protection to ensure that people are heavily disincentivized to cheat at sports betting. Not that people don't do it anyway.
Poker is the odd business out here – it has no single global regulatory body and little to no legal threat to the cheaters. Cheaters in casinos and at sports betting are running a much higher monetary and criminal punishment risk.
This is not news
Pads complained that he's been fighting this battle for over a decade, and I believe him. I've been around this business professionally for over 20 years. Every time something like this comes up, the players make the same complaint.
The answer will always be the same, so long as data protection laws and information asymmetry make it a bad bet for poker companies to share information about suspected cheaters.
I'm a poker player first and foremost. I can't imagine how frustrating and soul-crushing it must be to discover that somebody has been watching your hole cards.
You're playing a game where you think you have an edge, and you devote your life to studying and playing well. In some ways, it must almost be a relief to learn that no, you don't suck at poker – somebody was cheating you. On the other hand, being a victim of that kind of scam brings its own bruises on the soul.
But this is the world that we live in. There are literally millions of dollars in play here. Bad actors will continue to do whatever they can to get their hands on some of that money. When you play on unregulated grey market sites, you have accepted the concomitant risk, and people such as Leonard and Morón should be more aware of this than most.
Even on 'fully legal' sites (e.g. U.S. states with regulated online poker), cheaters are unlikely to face criminal justice. While cheating at online poker is against the law in (e.g.) Nevada, the operators don't seem interested in publicly unveiling cheaters.
My message to Patrick Leonard, Ignacio Morón, and anybody else playing online poker anywhere: use the best security hygiene you can. Get that security reviewed by somebody who really knows what they're doing. If you see something wrong on a site where you play, say something to that operator. Get everybody involved to say something to the operator, and show your work.
But don't hold your breath waiting for operators to share information about suspected cheaters.