From Robocalls to Zero-Days: The Shadowy Pivot of Wohl and Burkman

A Virginia-based cybersecurity startup promising multi-million dollar payouts for high-end software vulnerabilities has emerged as the latest venture of two of America’s most notorious political provocateurs. IRIS C2, a company claiming to specialize in offensive cyber capabilities, is the newest project operated by Jacob Wohl and Jack Burkman—a duo whose shared history is defined by a decade of fraud, felony convictions, and a long trail of fabricated intelligence operations.

The company, which maintains a public presence on X (formerly Twitter) and LinkedIn, has aggressively courted elite vulnerability researchers with the promise of "seven-figure" payouts for zero-day exploits. However, behind the veneer of a high-tech government contractor lies a business entity, Calvexa Group LLC, controlled by men whose careers have been built on deception rather than digital security.

The Rise of IRIS C2: Marketing the Offensive

Since its inception in January 2025, the X account @C2IRIS has rapidly accumulated over 4,000 followers, positioning itself as a hub for discourse on AI, software exploits, and offensive security. The company claims to be headquartered in McLean, Virginia, and holds itself out as a specialized vendor capable of delivering "full capabilities across all major platforms."

On its website, irisc2[.]com, the firm outlines a tiered compensation structure that would be the envy of any legitimate cybersecurity firm. Payouts for verified, operational exploits range from $10,000 to a staggering $7 million. In its recruitment efforts, the company explicitly claims to prioritize raw talent over formal credentials, stating in a pinned post that it seeks "junior engineers with raw talent/extremely high IQ" and maintains a policy of indifference toward traditional degrees or industry tenure.

Yet, industry experts note that the market for zero-day exploits—vulnerabilities unknown to the software developer—is typically a highly clandestine, vetted space. While government contractors do indeed pay significant premiums for such research, they rarely operate with the performative, public-facing bravado displayed by IRIS C2.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A Chronology of Deception

To understand the skepticism surrounding IRIS C2, one must look at the long, litigious history of its operators. The career trajectories of Wohl and Burkman are not those of technology entrepreneurs, but of serial agitators who have frequently leveraged the guise of professional organizations to mask partisan smear campaigns.

The Era of "Fake Intelligence"

For years, the pair operated a series of short-lived, shell-like entities designed to manufacture political crises. Their playbook consistently involved creating fake intelligence firms to lend credibility to fabricated claims.

  • 2018-2019: The duo targeted high-profile public figures, including then-FBI Director Robert Mueller and Democratic presidential candidate Pete Buttigieg, with elaborate, baseless sexual assault allegations. These efforts were largely debunked by journalists and law enforcement.
  • 2019: The pair hosted press conferences to push false claims of extramarital affairs involving Senator Elizabeth Warren and then-candidate Kamala Harris.
  • 2024: A report by Politico revealed the pair had launched an AI-powered lobbying platform, "LobbyMatic," under pseudonyms. Wohl operated as "Jay Klein," while Burkman utilized the alias "Bill Sanders." The company collapsed when employees discovered the true identities of their employers, leading to mass resignations.

The Legal Reckoning

The consequences of these operations have been severe. Following the 2020 U.S. Presidential Election, Wohl and Burkman were indicted for a massive robocall campaign that targeted minority voters in Detroit and other battleground areas with misinformation regarding mail-in ballots.

  • 2022: The pair pleaded guilty to felony telecommunications fraud in Ohio, resulting in fines, probation, and mandatory community service.
  • 2023: The Federal Communications Commission (FCC) hit the duo with a $5.1 million fine—the largest of its kind under the Telephone Consumer Protection Act—for their role in orchestrating the illegal robocall scheme.
  • 2023: A New York civil court ruled that they had violated civil and human rights laws, forcing a $1 million settlement.
  • 2025: After exhausted appeals, both were sentenced to probation for their roles in the 2020 election interference efforts.

Furthermore, Jacob Wohl’s history of financial malfeasance predates his political career. By age 17, he was already styling himself as the "Wohl of Wall Street." In 2017, the Arizona Corporation Commission charged him with securities fraud, and in 2019, he pleaded guilty in California to four felony counts related to the sale of unregistered securities.

Supporting Data: The Calvexa Connection

Public records confirm that IRIS C2 is a project of Calvexa Group LLC, a company registered in Virginia. The company’s official website, calvexagroup[.]com, serves as a redirect to the IRIS C2 portal. While G2Exchange—a platform that tracks federal contracting—lists Calvexa as a registered federal contractor, there is no evidence that the company has secured any legitimate direct government contracts.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

The business address associated with Calvexa in Arlington, Virginia, is the same location occupied by Burkman & Associates. When questioned about the nature of IRIS C2, Jack Burkman directed all inquiries to Jacob Wohl, confirming the latter’s central role in the operation.

Recent reports further complicate the narrative. In March 2026, investigative journalist Molly White revealed that the duo had accepted a $300,000 retainer from a Canadian cryptocurrency operator wanted by international authorities for the theft of $65 million. The pair were reportedly tasked with navigating a presidential pardon for the accused hacker, further cementing their reputation for involvement with high-risk, ethically dubious clientele.

Official Responses and Defensive Posturing

In an interview with KrebsOnSecurity, Jacob Wohl claimed that IRIS C2 has pivoted away from its original focus on penetration testing toward "phone-hacking services" for government entities. Despite his lack of formal computer science training, Wohl projected extreme confidence regarding his technical acumen.

"I know more about tech than anyone," Wohl asserted during the interview, claiming his knowledge is self-taught. "My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."

When pressed for evidence of government contracts, Wohl declined to provide specifics, citing national security concerns. He further claimed the company employs approximately 40 staff members, yet noted that none are permitted to disclose their employment on professional networks like LinkedIn, ostensibly for "operational security."

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Implications for the Cybersecurity Industry

The emergence of IRIS C2 raises significant red flags for the cybersecurity industry. The "bug bounty" and exploit acquisition market relies heavily on trust, reputation, and verifiable expertise. By injecting a company run by convicted fraudsters into this ecosystem, there is a risk of both compromising security researchers who may unwittingly provide sensitive data to bad actors and creating a vector for illicit trade.

Risks to Researchers

Security researchers who engage with IRIS C2 risk not only their reputations but also their professional futures. Providing exploit code to a firm with no established history of responsible disclosure—and whose operators have a documented history of weaponizing information—could lead to legal complications or the misuse of vulnerabilities for non-defensive purposes.

The "Clout-Chasing" Factor

The cybersecurity community has long been a home for an eclectic mix of talent, ranging from ethical hackers to those operating in the gray market. However, industry veterans emphasize that the "offensive security" sector is typically characterized by discretion. The brazen, public-facing marketing of IRIS C2 is fundamentally at odds with the professional standards required for sensitive government-level work.

As the industry continues to monitor IRIS C2, the consensus among security experts is one of extreme caution. With a track record of aliases, fake intelligence, and felony fraud, the transition of Jacob Wohl and Jack Burkman into the world of zero-day exploits appears less like a genuine pivot into technology and more like the latest iteration of a pattern that has consistently sought to exploit, deceive, and manipulate for personal gain. Whether or not the duo can actually deliver on their promises of "exquisite capabilities" remains to be seen, but their past provides a stark warning for any researcher considering an offer from the McLean-based firm.

Leave a Reply

Your email address will not be published. Required fields are marked *