From Robocalls to Zero-Days: The Shadowy Rise of IRIS C2 and Its Discredited Founders

In the high-stakes, hyper-competitive world of cybersecurity, the acquisition of “zero-day” vulnerabilities—undisclosed security flaws in popular software—is a multi-billion dollar industry. It is a sector typically dominated by shadowy government contractors, elite academic researchers, and highly vetted intelligence entities. However, a new player has emerged on the scene, promising payouts of up to $7 million for exploit research.

IRIS C2, a McLean, Virginia-based firm, has rapidly gained attention on social media, amassing over 4,000 followers on X (formerly Twitter) since January 2025. Yet, behind the polished facade of this offensive cybersecurity startup lies a controversial reality: the company is helmed by Jack Burkman and Jacob Wohl, a pair of notorious political operatives and convicted felons whose previous business ventures have been defined by fraud, fabrication, and federal indictments.

The Business of Exploitation: What is IRIS C2?

IRIS C2 positions itself as a premier provider of offensive cyber capabilities. Its online presence is characterized by aggressive recruitment tactics, explicitly targeting "junior engineers with raw talent" while dismissing the necessity of academic degrees or traditional industry credentials.

The firm’s website, irisc2[.]com, functions as a marketplace for digital weaponry. It claims to acquire "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms." The allure of million-dollar payouts is designed to attract top-tier talent, a strategy that the company boasts has resulted in an "overwhelming" volume of job applications.

Behind the scenes, the entity is linked to Calvexa Group LLC, a Virginia-based business registered as a federal contractor. Despite this registration, government procurement databases indicate that Calvexa Group has yet to secure a direct federal contract. The company’s digital infrastructure is intentionally opaque; its contact page redirects users to the IRIS C2 domain, effectively shielding the true nature of its corporate operations from casual scrutiny.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A History of Deception: The Wohl-Burkman Chronology

To understand the skepticism surrounding IRIS C2, one must examine the track record of its principals. Jacob Wohl, now 28, first garnered national headlines as a teenage hedge fund manager, famously branding himself the "Wohl of Wall Street." That early venture ended in 2017 when the Arizona Corporation Commission charged his investment funds with 14 counts of securities fraud. By 2019, Wohl had pleaded guilty to four felony counts of selling unregistered securities in California.

His partnership with 60-year-old lobbyist Jack Burkman has been even more volatile. Their history is marked by a series of elaborate disinformation campaigns designed to target political figures:

  • 2018–2019: The duo created fake intelligence companies to propagate fabricated sexual assault allegations against FBI Director Robert Mueller and Democratic presidential candidate Pete Buttigieg.
  • 2019: They staged press conferences to baselessly allege extramarital affairs involving Senator Elizabeth Warren and then-candidate Kamala Harris.
  • 2020: In the aftermath of the presidential election, they orchestrated a massive robocall campaign targeting voters in battleground states with false information regarding mail-in ballots.
  • 2022–2025: The consequences of their actions caught up with them. In 2022, they pleaded guilty to felony telecommunications fraud in Ohio. By late 2025, they were sentenced to probation for a separate 15-count felony indictment in Cleveland regarding a scheme to suppress the Black vote in Detroit.
  • 2023: The Federal Communications Commission (FCC) levied a record-breaking $5.1 million fine against the pair—the largest in the agency’s history under the Telephone Consumer Protection Act.

From LobbyMatic to IRIS C2: A Pattern of Pseudonyms

The transition into the cybersecurity sector follows a recent, failed venture known as "LobbyMatic." As reported by Politico in 2024, the duo operated this AI-based lobbying platform using aliases—Wohl as "Jay Klein" and Burkman as "Bill Sanders." The deception was so pervasive that several employees only discovered their employers’ true identities after they had resigned from the company.

This pattern of behavior suggests that IRIS C2 may be the latest iteration in a long-standing strategy of using sophisticated technical branding to mask questionable business practices. When confronted about these past failures, Wohl maintains an air of bravado, claiming, "I know more about tech than anyone." He describes his current role as taking "preliminary" vulnerability findings from researchers and refining them into "stable and reliable" exploits.

Supporting Data and Industry Implications

The market for security vulnerabilities is a complex ecosystem. While it includes legitimate bug bounty programs (such as those run by Google, Microsoft, and Apple), it also features a gray market where high-end exploits are sold to state actors and intelligence agencies.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Legitimate government contractors in this space are famously circumspect. They operate behind layers of security clearance and non-disclosure agreements. IRIS C2’s "brazen" public marketing—soliciting exploits on social media and cold-calling researchers at cybersecurity conferences—is viewed by many in the industry as highly irregular.

"They were pestering people at a regional conference about selling their research," one attendee told KrebsOnSecurity, noting that such aggressive, unvetted outreach is a major red flag for established security professionals.

Furthermore, recent reporting by Molly White suggests that the pair’s financial interests extend beyond traditional business. In early 2026, it was revealed that Burkman and Wohl were paid a $300,000 retainer by a Canadian cryptocurrency figure currently wanted for an alleged $65 million hacking scheme. Their stated goal was to secure a presidential pardon for the accused, highlighting a recurring theme of the pair inserting themselves into high-stakes legal and criminal matters.

Implications for National Security and the Tech Sector

The presence of IRIS C2 raises significant questions regarding the oversight of federal contractors. While Calvexa Group LLC is registered as a contractor, the lack of transparency surrounding its operations, combined with the criminal history of its leadership, poses a potential liability.

1. Security of Vulnerability Research

If IRIS C2 is indeed acting as a broker for zero-day exploits, the question of where those vulnerabilities end up is paramount. The global market for these tools is often unregulated, and there is a high risk that exploits purchased by entities with a history of deception could be sold to foreign adversaries or criminal syndicates.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

2. Operational Security and Employee Risk

Wohl claims the company employs roughly 40 people, none of whom are permitted to list their employment on professional networks like LinkedIn. This "operational security" prevents employees from establishing a professional footprint and obscures the company’s actual workforce. Given that previous employees of the duo’s ventures have been kept in the dark about their true identities and legal standing, the risks to prospective employees are severe.

3. Regulatory Scrutiny

The FCC’s record-breaking fines and the multi-state felony convictions of Burkman and Wohl serve as a warning to the tech sector. While they currently operate under the guise of a cybersecurity startup, the regulatory and legal trajectory of their previous companies suggests that IRIS C2 is unlikely to remain under the radar for long.

Conclusion

IRIS C2 stands as a bizarre intersection of the high-tech vulnerability market and the low-road political activism that has defined the careers of Jack Burkman and Jacob Wohl. While they claim to be building "exquisite capabilities," their history suggests a primary expertise in the art of the grift. For the cybersecurity community, the firm represents a cautionary tale: in an industry built on trust and technical integrity, the presence of actors with a documented history of fraud serves as a reminder that not all that glitters—or promises million-dollar payouts—is gold.

As investigations into the company continue, the central question remains: how much longer can a firm run by convicted fraudsters continue to present itself as a legitimate partner in the defense of global software infrastructure? For now, the cybersecurity world is watching with a mixture of skepticism and profound concern.

Leave a Reply

Your email address will not be published. Required fields are marked *