From Robocalls to Zero-Days: The Shadowy Pivot of Jack Burkman and Jacob Wohl

In the high-stakes, hyper-competitive world of offensive cybersecurity—where government agencies and private firms pay millions for "zero-day" exploits capable of piercing the world’s most secure software—reputation is usually the primary currency. Trust, vetting, and technical pedigree typically serve as the gatekeepers to a market shrouded in secrecy. However, a new player has emerged that defies these conventions, operating with a bravado that has alarmed the intelligence and security communities.

IRIS C2, a Virginia-based entity, is aggressively courting the world’s most talented vulnerability researchers with promises of seven-figure payouts. Yet, behind the polished facade of this "cyber-capabilities" firm lie two of the most notorious figures in recent American political history: Jack Burkman and Jacob Wohl. The pair, previously known for a string of failed, fraudulent, and often bizarre political schemes, are now attempting to pivot into the lucrative world of cyber-warfare.

The Genesis of IRIS C2: A High-Stakes Facade

Since its quiet emergence on X (formerly Twitter) in January 2025, the account @C2IRIS has rapidly accumulated over 4,000 followers. The account projects an image of cutting-edge expertise, posting technical commentary on software exploits and artificial intelligence. The firm’s website, irisc2[.]com, claims to provide "offensive cybersecurity capabilities" and boasts of acquiring everything from "individual primitives" to "full-chain" exploits across major platforms.

The company’s recruitment pitch is remarkably blunt. A pinned post on their social media profile declares: "Our business model is this: Attract the very best vulnerability researchers and exploit developers in the world… We don’t care if they have a college degree or industry experience."

While the offer of up to $7 million for reliable, high-value exploits is designed to lure top-tier talent, industry experts are baffled. The market for zero-day vulnerabilities is typically characterized by extreme circumspection. Government contractors, who often purchase such exploits for intelligence purposes, usually maintain long-standing, vetted relationships with researchers. The brazen, public nature of IRIS C2’s recruitment drive stands in stark contrast to the shadowy, discreet nature of the industry.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

A History of Fabrications: The Burkman-Wohl Timeline

To understand the skepticism surrounding IRIS C2, one must look at the track record of its operators. The history of Jack Burkman and Jacob Wohl is a documented catalog of influence operations, fraudulent investment schemes, and legal battles.

The Early Years and "Wohl of Wall Street"

Jacob Wohl first gained notoriety as a teenager, branding himself "Wohl of Wall Street" and appearing on cable news to discuss his supposed investment acumen. This persona collapsed in 2017 when the Arizona Corporation Commission charged him and his funds with 14 counts of securities fraud, resulting in a $35,000 restitution order. In 2019, he pleaded guilty in California to four felony counts of selling unregistered securities, marking the beginning of a persistent pattern of legal trouble.

The Political Smear Campaigns

Following his pivot from finance, Wohl joined forces with veteran lobbyist Jack Burkman. Together, the pair orchestrated a series of "intelligence" operations that were widely debunked. Their efforts included:

  • Fabricated Sexual Assault Claims: In 2018, they attempted to smear then-FBI Director Robert Mueller with false allegations.
  • Political Framing: In 2019 and 2020, they held press conferences making baseless claims of extramarital affairs against Sen. Elizabeth Warren and then-candidate Kamala Harris.
  • The Pete Buttigieg Affair: The duo unsuccessfully attempted to manufacture a scandal involving the former mayor of South Bend, Indiana.

The Robocall Prosecution

Perhaps their most significant legal defeat followed the 2020 presidential election. The duo orchestrated a massive robocall campaign in battleground states intended to suppress voter turnout by spreading misinformation about mail-in ballots. The fallout was severe:

  • Criminal Indictments: They were indicted in Cleveland on 15 felony counts for their role in the Detroit robocall scheme.
  • Sentencing: In late 2025, following a series of failed appeals, they were sentenced to probation.
  • Financial Penalties: In 2022, they pleaded guilty to a felony count of telecommunications fraud in Ohio. A year later, the FCC imposed a $5.1 million fine—the largest in the agency’s history under the Telephone Consumer Protection Act—for their illicit activities.

The LobbyMatic Deception

Even as recently as 2024, the pair was operating under pseudonyms. Reports from Politico revealed that they operated an AI-based lobbying firm called "LobbyMatic," using the aliases "Jay Klein" and "Bill Sanders." The firm claimed to use advanced AI to influence legislation, a claim that was later exposed as largely fraudulent. Several employees resigned after discovering the true identities of their employers.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

The Cryptocurrency Connection

The depth of their involvement in illicit global activities was further illuminated in March 2026, when reports from journalist Molly White revealed that the duo had been paid a $300,000 retainer by a Canadian national. The client, a cryptocurrency fraudster wanted by the U.S. and other nations for his alleged role in the $65 million theft from KyberSwap and Indexed Finance, had hired the pair to lobby for a presidential pardon—a move that underscores their ongoing entanglement with individuals operating on the fringes of the law.

Implications for the Cybersecurity Industry

The emergence of IRIS C2 raises profound concerns regarding the security of the software supply chain and the integrity of the government contracting process. Government records indicate that IRIS C2 is linked to "Calvexa Group LLC," a registered federal contractor. While public records do not suggest that the company is currently fulfilling direct government contracts, its attempt to enter the space is viewed by many as an existential threat to the reputation of legitimate security firms.

The Technical Credibility Gap

When questioned about the technical validity of IRIS C2, Wohl displayed his trademark confidence, despite having no formal computer science training. "I know more about tech than anyone," he stated in an interview. "People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."

However, industry veterans point out that "exploit primitives" are not the same as functional, reliable zero-day exploits. The process of turning a raw, unstable flaw into a "full-chain" capability—a weaponized exploit that can bypass modern security mitigations—requires rigorous, high-level engineering. The suggestion that Wohl and his team possess the expertise to refine these tools, while operating under a veil of pseudonymity and history of fraud, is met with extreme derision.

Operational Risks and National Security

For the cybersecurity industry, the presence of IRIS C2 is not merely an annoyance; it is a potential national security concern. If a company operated by individuals with a history of foreign and domestic disinformation campaigns manages to gain access to, or purchase, critical vulnerability research, the potential for misuse is significant.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Furthermore, the "operational security" excuse—whereby the firm claims employees are prohibited from listing their work on LinkedIn—creates a vacuum of accountability. If the employees of IRIS C2 are, in fact, unaware of their employers’ backgrounds, they are effectively working for an entity that lacks the basic moral and legal standing required to handle sensitive security research.

Conclusion: A Cautionary Tale

The trajectory of Jack Burkman and Jacob Wohl from the fringes of political activism to the center of the offensive cybersecurity market is a stark reminder of how the digital age rewards those who can monetize chaos. While they claim to be building a "high-IQ" firm of elite researchers, the reality appears to be another iteration of their established pattern: high-concept branding, inflated promises, and a deep, systemic disregard for truth.

For the cybersecurity community, the lesson is clear: in an industry where "zero-day" exploits can influence the fate of nations, the background of the buyer is just as important as the quality of the code. As regulators and industry watchdogs continue to monitor the activities of Calvexa Group and IRIS C2, the question remains whether this latest venture will suffer the same fate as their previous efforts, or if they have finally found a market that is as volatile and unregulated as their own business practices.

Leave a Reply

Your email address will not be published. Required fields are marked *