In the shadowy, high-stakes ecosystem of zero-day vulnerability trading—a market typically reserved for elite, secretive firms and national intelligence agencies—a new player has emerged, promising payouts of up to $7 million for software exploits. But behind the polished facade of IRIS C2, a McLean, Virginia-based cybersecurity startup, lies a history of political deception, federal criminal convictions, and a well-documented penchant for fabrication.
The firm, which has gained significant traction on X (formerly Twitter) since its launch in early 2025, is the latest venture by Jacob Wohl and Jack Burkman, two figures better known for their roles in orchestrating far-right conspiracy theories and illegal robocall campaigns than for expertise in software engineering. As they pivot toward the lucrative world of offensive cyber warfare, their entry into the market has raised alarms among security professionals and federal investigators alike.
The Business Model: High-Stakes Exploits and "Raw Talent"
IRIS C2, which officially identifies itself as an offensive cybersecurity provider, operates with a degree of bravado rarely seen in the industry. Its primary mission is the acquisition of "zero-day exploits"—undisclosed vulnerabilities in software that allow attackers to bypass security measures. The company claims to be scouting for top-tier talent, explicitly stating in its recruitment messaging that it values "raw talent" and "extremely high IQ" over traditional credentials like university degrees or formal industry experience.
The company’s website, irisc2.com, serves as a marketplace for digital weaponry, advertising the purchase of primitives, partial chains, and full-scale capabilities across all major software platforms. The financial incentives are staggering, with publicly posted payouts ranging from $10,000 to $7 million. While legitimate firms in this space often handle such transactions with extreme discretion, IRIS C2 utilizes social media platforms like LinkedIn and X to broadcast its needs, an approach that industry veterans describe as both "brazen" and "unorthodox."
A Pattern of Deception: The Chronology of Controversy
To understand the nature of IRIS C2, one must look at the track record of its principals. Jacob Wohl, 28, and Jack Burkman, 60, have spent the better part of the last decade entangled in a series of legal and ethical crises that have consistently involved the use of fake companies and pseudonyms.

The Era of "Fake Intelligence"
Before turning their sights to cybersecurity, the duo operated as a self-styled political intelligence team. Their primary tactic involved the creation of front companies to disseminate fabricated claims against political rivals. Between 2018 and 2020, they were linked to a string of baseless allegations, including:
- The Mueller/Buttigieg Smear Campaigns: Fabricated sexual assault allegations leveled against former FBI Director Robert Mueller and then-presidential candidate Pete Buttigieg.
- Targeting Public Figures: Orchestrating press conferences to falsely allege extramarital affairs involving Senator Elizabeth Warren and Kamala Harris.
The Robocall Prosecution
The pair’s activities eventually moved from smear tactics to criminal activity. In the wake of the 2020 U.S. presidential election, Wohl and Burkman were indicted in Ohio on 15 felony counts related to a massive robocall scheme designed to suppress the vote in Detroit. The scheme, which utilized thousands of automated calls to disseminate false information regarding mail-in ballots, resulted in a long-standing legal battle. In late 2025, after exhausting their appeals, both were sentenced to probation.
Fraud and Regulatory Scrutiny
The duo’s history of financial and regulatory transgressions is equally extensive:
- 2017: The Arizona Corporation Commission charged Wohl with 14 counts of securities fraud related to his investment funds.
- 2019: Wohl pleaded guilty in California to felony charges of selling unregistered securities.
- 2023: The FCC imposed a historic $5.1 million fine against the pair—the largest in the agency’s history under the Telephone Consumer Protection Act—for their illicit robocall operations.
- 2024: A Politico investigation exposed "LobbyMatic," an AI-based lobbying firm they operated under the aliases "Jay Klein" and "Bill Sanders." The company collapsed after employees discovered their employers’ true identities and the fraudulent nature of the business.
Supporting Data: The "Calvexa Group" Connection
Corporate records provide the clearest link between the duo and their new venture. Government contracting databases, including G2Exchange, identify irisc2.com as an asset of Calvexa Group LLC. While Calvexa is registered as a federal contractor, the company lacks a track record of successful government awards.
When researchers traced the incorporation address for Calvexa Group in Arlington, Virginia, they found the location occupied by Burkman & Associates. When questioned about the nature of the company, Jack Burkman deflected, pointing inquiries toward Jacob Wohl. This structure—a shell-like company acting as a front for a more controversial operation—mirrors the exact methodology used by the pair during their LobbyMatic venture.

Official Responses and The "Expert" Persona
In an interview with KrebsOnSecurity, Jacob Wohl maintained that IRIS C2 is a legitimate operation. He insisted that Jack Burkman has no role in the day-to-day management of the startup. When pressed on his own lack of formal technical training, Wohl leaned into his long-standing persona as a self-taught prodigy.
"I know more about tech than anyone," Wohl stated. "My background has always been extremely technical… I’m able to create spectacularly exquisite capabilities that would make your head spin."
Wohl further claimed that the firm employs approximately 40 individuals. However, he admitted that none of these employees are permitted to list their employment on professional networks like LinkedIn, citing "operational security." This lack of transparency, coupled with the fact that the company has been seen "pestering" attendees at cybersecurity conferences to sell their research, has led many in the security community to view the company with extreme skepticism.
Implications: The Risks of "Amateur" Arms Dealing
The rise of IRIS C2 highlights a growing concern within the cybersecurity community: the "democratization" of the offensive exploit market. Historically, the trade of zero-day vulnerabilities was confined to a handful of well-vetted, highly regulated entities. By injecting themselves into this space, Wohl and Burkman represent a dangerous variable.
1. Security Integrity and Vulnerability Management
There is significant concern regarding what becomes of the vulnerabilities acquired by a firm with no established ethical guidelines or security infrastructure. If these exploits are not handled with the extreme rigor required by professional contractors, they could easily leak into the hands of malicious state actors or cybercriminal syndicates, potentially compromising global software security.

2. The "Pardon-for-Hire" Connection
The concerns surrounding IRIS C2 were further compounded by recent reports from journalist Molly White, who noted that the pair had been paid a $300,000 retainer by a Canadian national wanted by the U.S. government for a $65 million cryptocurrency theft. Their alleged mission: to secure a presidential pardon for the suspect. This connection raises questions about whether IRIS C2 is being used as a financial vehicle to facilitate legal interventions for international criminals, rather than as a legitimate defense-tech company.
3. Impact on Government Contracting
The fact that a business with such a significant criminal history can register as a federal contractor, even without winning direct contracts, speaks to potential gaps in the vetting process for the defense industrial base. The possibility that federal government officials might inadvertently engage with these individuals poses a severe security risk, both in terms of sensitive information exposure and the potential for public scandal.
Conclusion
IRIS C2 sits at the intersection of extreme technological ambition and a documented history of fraud. While the firm promises to revolutionize the way governments acquire offensive cyber capabilities, its leadership—defined by a long trail of failed ventures, felony convictions, and deceptive practices—suggests a far different reality.
For the cybersecurity industry, the presence of such a firm is a stark reminder of the risks inherent in an unregulated, high-profit market. As federal agencies and private security firms continue to navigate the complexities of the digital age, the "Wohl and Burkman" model of entrepreneurship serves as a cautionary tale of what happens when the lines between political provocation and national security are blurred by those with a history of exploiting the very systems they claim to support.
