In the high-stakes, shadow-filled marketplace of zero-day exploits—where a single line of code can command a seven-figure payday—a new player has emerged, promising to disrupt the status quo. IRIS C2, a Virginia-based entity, claims to be a cutting-edge offensive cybersecurity firm hunting for the world’s most dangerous software vulnerabilities. However, behind the facade of million-dollar payouts and technical prowess lies a familiar pair of architects: Jacob Wohl and Jack Burkman, two figures whose careers are defined by a long, litigious trail of disinformation, fraudulent schemes, and felony convictions.
The Rise of IRIS C2: A Digital Enigma
Since its inception in January 2025, the X (formerly Twitter) account @C2IRIS has rapidly accumulated over 4,000 followers. The account presents a polished, if aggressive, persona, frequently broadcasting updates on AI-driven exploits and software vulnerabilities. Its pinned post serves as a manifesto of sorts: a call to arms for "junior engineers with raw talent" and "extremely high IQ," explicitly stating that traditional credentials like college degrees or industry experience are irrelevant.
The company’s primary digital storefront, irisc2.com, serves as the public face of this operation. It promises payouts ranging from $10,000 to a staggering $7 million for "zero-day exploits, individual primitives, partial chains, and full capabilities." These figures place IRIS C2 squarely in the territory of elite, state-aligned cyber-arms dealers. Yet, unlike established firms that operate in the shadows of the defense industrial base, IRIS C2 has taken a brazen, public-facing approach to recruitment that has left industry veterans scratching their heads.
Chronology of a Controversial Partnership
To understand the nature of IRIS C2, one must look at the men behind the curtain. Jack Burkman and Jacob Wohl are not newcomers to the business of deception; they are repeat offenders whose careers have spanned from disgraced hedge fund management to the orchestrating of national political smear campaigns.
The Foundation of Deceit
Long before they pivoted to cybersecurity, Wohl and Burkman were infamous for their "intelligence" startups. These companies were frequently nothing more than vehicles for political theater. They became household names for concocting elaborate, false narratives—most notably the fabricated sexual assault allegations against then-FBI Director Robert Mueller and Pete Buttigieg during the 2020 election cycle. Their playbook was consistent: establish a fake firm, create a digital footprint, and release sensationalist claims that collapsed under the slightest journalistic scrutiny.

The Robocall Era and Legal Reckoning
The pair’s shift from political agitators to legal defendants was cemented by their 2020 election interference efforts. Wohl and Burkman were the architects behind a massive robocall campaign targeting voters in battleground states with disinformation regarding mail-in ballots. The fallout was swift and severe:
- 2022: The duo pleaded guilty to a single felony count of telecommunications fraud in Ohio, resulting in fines, probation, and community service.
- 2023: A New York civil court judge ruled that the pair had violated state and federal civil rights laws, forcing a $1 million settlement.
- 2023: The Federal Communications Commission (FCC) issued a record-breaking $5.1 million fine against the pair, the largest in the history of the Telephone Consumer Protection Act.
- 2025: After a protracted legal battle, they were sentenced to probation in Cleveland regarding 15 felony counts tied to a voter suppression scheme targeting Detroit.
The Pivot to "LobbyMatic" and Beyond
Before IRIS C2, the duo operated a firm called LobbyMatic, which claimed to use artificial intelligence to revolutionize political lobbying. An investigation by Politico revealed that the company was a sham operated under pseudonyms—Wohl went by "Jay Klein," while Burkman used "Bill Sanders." The company collapsed after employees discovered their employers’ true identities and realized the "AI-driven" platform was largely smoke and mirrors.
Supporting Data: The Anatomy of a Cybersecurity Fraud?
The connection between IRIS C2 and the duo was confirmed through corporate filings and physical proximity. Government contracting databases identify irisc2.com as being operated by Calvexa Group LLC, a Virginia-based entity. The contact information for Calvexa Group redirects directly to the IRIS C2 website. When investigators traced the business address listed for Calvexa, they found themselves at the doorstep of Jack Burkman’s lobbying firm.
Furthermore, recent reports have surfaced regarding the duo’s involvement with international bad actors. In early 2026, investigations indicated that Burkman and Wohl had accepted a $300,000 retainer from a Canadian individual wanted by the U.S. government for a $65 million cryptocurrency theft. The goal, allegedly, was to lobby for a presidential pardon—a task consistent with the duo’s history of "fixer" operations.
Official Responses and the "Technical" Defense
In an exclusive interview, Jacob Wohl maintained a posture of supreme confidence, distancing Burkman from the daily operations of IRIS C2 while confirming his own leadership role. When asked about his lack of formal training in computer science or software engineering, Wohl dismissed the necessity of such qualifications.

"I know more about tech than anyone," Wohl stated. "My background has always been extremely technical… I’m able to create spectacularly exquisite capabilities that would make your head spin."
Wohl claims the company currently employs 40 individuals. However, he admitted that none of these employees list their work on platforms like LinkedIn, citing "operational security." He characterized the business as a firm that takes "preliminary" vulnerability findings—such as a flaw in a phone’s media decoder—and transforms them into stable, reliable, and "operational" exploits. Yet, when pushed for details regarding his claimed federal government contracts, Wohl retreated behind the veil of national security, refusing to provide specifics.
Implications for the Cybersecurity Industry
The emergence of IRIS C2 raises alarming questions about the integrity of the offensive security market. The vulnerability research community is a delicate ecosystem where trust is paramount. By interjecting a firm led by individuals with a documented history of fraud, the barrier between legitimate research and criminal enterprise is being blurred.
The Risk to Talent
The primary victims of this venture may well be the "junior engineers" the company seeks to recruit. By promising million-dollar payouts, Wohl and Burkman are effectively dangling a carrot before young researchers who may be unaware that their work could be funneled into a company with no track record, no legitimate security pedigree, and leadership currently under severe legal and financial scrutiny.
The Threat to National Security
The claim that IRIS C2 sells to the government is the most concerning aspect of the entire operation. While government contractors are subject to rigorous vetting and oversight, the "grey market" of exploit acquisition is notoriously opaque. If a firm managed by convicted felons and known purveyors of disinformation can successfully position itself as a vendor for sensitive government capabilities, it suggests a profound failure in the procurement and vetting processes meant to protect the nation’s digital infrastructure.

As the cybersecurity industry continues to professionalize, the presence of IRIS C2 serves as a stark reminder of the "wild west" elements that persist. Whether the company is a legitimate attempt at a business pivot or simply the latest "shell" for a pair of notorious provocateurs, the implications remain the same: the digital security of the nation is too critical to be left in the hands of those who have made a career out of bending the truth.
For now, the cybersecurity world remains on high alert, watching to see if IRIS C2 delivers the "exquisite capabilities" it promises, or if it will inevitably join the long, inglorious list of failed ventures left in the wake of Wohl and Burkman.
