In the shadows of the cybersecurity industry—a sector traditionally characterized by quiet expertise, rigorous academic credentials, and institutional discretion—a new entity has emerged with the subtlety of a wrecking ball. IRIS C2, a McLean, Virginia-based startup, has begun dangling million-dollar bounties for "zero-day" software vulnerabilities, promising to revolutionize the market for offensive cyber capabilities. However, behind the slick web presence and the promise of lucrative payouts lies a partnership between two of the most infamous figures in American political disinformation: Jack Burkman and Jacob Wohl.
The Rise of IRIS C2: A Digital Enigma
Since its quiet inception in January 2025, the X (formerly Twitter) account @C2IRIS has rapidly accumulated over 4,000 followers. The account presents a persona of technical sophistication, frequently posting about AI, software exploits, and the "raw talent" required to join their ranks.
"Our business model is this," reads a pinned post on the company’s profile. "Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience."
The company’s website, irisc2[.]com, functions as a recruitment portal for the high-stakes world of exploit acquisition. The site claims to be in the business of securing "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms." The price tags are staggering: payouts range from $10,000 to as much as $7 million, depending on the target’s reliability and operational value.
While the firm claims to be an powerhouse of offensive cybersecurity, government contracting databases offer a more pedestrian view. According to the federal contracting portal g2exchange.com, the operation is run through a shell entity known as Calvexa Group LLC. While Calvexa is registered as a federal contractor, it possesses no visible, direct government contracts—a startling revelation for a company that claims to be a major player in the national security ecosystem.

A Chronology of Controversy: From Lobbying to Litigation
The involvement of Jack Burkman and Jacob Wohl in the high-stakes cybersecurity market is not a pivot toward a legitimate career; it is the latest chapter in a long history of deceptive ventures. To understand the risks posed by IRIS C2, one must look at the duo’s track record of utilizing fake corporate fronts to achieve political and financial ends.
The Era of "Fake Intelligence"
For years, Burkman and Wohl have operated in the gray zones of American political life, frequently utilizing pseudonyms and fabricated entities to smear public figures. Their history includes:
- 2018-2019: The duo orchestrated a series of bizarre, failed smear campaigns against high-profile officials, including then-FBI Director Robert Mueller and then-Mayor Pete Buttigieg. These campaigns relied on manufactured sexual assault allegations that quickly unraveled under journalistic scrutiny.
- 2019: The pair held press conferences falsely alleging extramarital affairs involving Senator Elizabeth Warren and then-candidate Kamala Harris.
- 2020: The "robocall" scandal. Burkman and Wohl were indicted on 15 felony counts in Ohio for orchestrating a campaign of automated calls in Detroit intended to suppress the Black vote by spreading misinformation about mail-in ballots.
- 2022-2023: Legal consequences caught up with the pair. In 2022, they pleaded guilty to a felony charge of telecommunications fraud in Ohio, resulting in fines, probation, and community service. In 2023, the FCC hit the duo with a record-breaking $5.1 million fine—the largest of its kind—for their role in the robocall campaigns.
The Pivot to "LobbyMatic"
Before the birth of IRIS C2, the pair attempted to break into the tech industry with "LobbyMatic," an AI-based lobbying platform. As reported by Politico in 2024, the company was a house of cards. Wohl operated under the alias "Jay Klein," while Burkman used the name "Bill Sanders." Employees were left blindsided; two staff members resigned immediately upon discovering the true identities of their employers, and others remained unaware of the deception until after their departure.
The Crypto Connection
The duo’s recent activities extend into the murky world of international finance. In early 2025, reports emerged indicating that Burkman and Wohl were paid a $300,000 retainer by a Canadian cryptocurrency fraudster. The individual, who is wanted by the United States for allegedly stealing $65 million from crypto platforms like KyberSwap, hired the pair to lobby for a presidential pardon—a task for which they are entirely unqualified, given their lack of legal standing or legitimate lobbying influence.
Supporting Data: The Illusion of Technical Expertise
In an interview with KrebsOnSecurity, Jacob Wohl—now 28—insisted that his partner, Jack Burkman, is not involved in the day-to-day operations of IRIS C2. Wohl, who has no formal education in computer science or cybersecurity, claimed his technical prowess is entirely self-taught.

"I know more about tech than anyone," Wohl stated during the interview. "My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."
Despite these claims, Wohl’s professional history is defined by financial fraud, not software engineering. In 2017, he was charged by the Arizona Corporation Commission with 14 counts of securities fraud related to his investment funds. In 2019, he pleaded guilty in California to four felony counts of selling unregistered securities.
When asked about the mechanics of IRIS C2, Wohl claimed the company has approximately 40 employees. However, he admitted that none of these employees are allowed to list their employment on LinkedIn due to "operational security." This lack of transparency, combined with the firm’s inability to point to a single verifiable government contract, raises significant red flags for any researcher or investor considering engagement with the firm.
Official Responses and Industry Skepticism
The cybersecurity community has met IRIS C2 with a mixture of confusion and derision. Unlike established firms in the vulnerability research space, which operate with high levels of professional vetting and rigorous peer review, IRIS C2’s approach is described by insiders as "brazen" and "amateurish."
Government contractors who legitimately deal in vulnerability research typically operate in highly regulated, private environments. They do not recruit via Twitter threads or boast about "spectacularly exquisite capabilities" to the public.

When pressed on his government contracts, Wohl declined to provide details, claiming he was "not at liberty to speak publicly" about them. Such responses are a hallmark of the "security through obscurity" defense that the pair has used in previous ventures to avoid scrutiny.
Implications: The Risks of a "C2" Startup with a Criminal Pedigree
The rise of IRIS C2 carries profound implications for both the cybersecurity industry and the broader national security apparatus.
- Exploitation of Young Talent: By targeting junior engineers with promises of million-dollar payouts, IRIS C2 may be luring talented but inexperienced developers into a professional environment that lacks ethical oversight and legal standing.
- National Security Vulnerabilities: If IRIS C2 is indeed handling "zero-day" exploits, the question of their storage and security protocols becomes paramount. Given the pair’s history of data mismanagement and fraud, the potential for these vulnerabilities to be leaked or mishandled poses a genuine risk to global software security.
- The Erosion of Credibility: The existence of such a company cheapens the legitimate work of vulnerability researchers. It allows bad actors to masquerade as legitimate contractors, potentially creating a "noise" layer that makes it harder for intelligence agencies to identify and procure genuine, high-value exploits.
- Legal Jeopardy: For those who choose to work with or provide research to IRIS C2, the risk of legal fallout is high. Given the duo’s history of felony convictions, financial fraud, and federal fines, any association with their business entities could expose researchers to future federal investigations or civil litigation.
As IRIS C2 continues to solicit researchers, the cybersecurity industry remains on high alert. For Jacob Wohl and Jack Burkman, this venture appears to be yet another attempt to leverage their infamy for profit. For the rest of the world, it is a reminder that in the digital age, the most dangerous "exploits" aren’t always found in software code—sometimes, they are found in the people running the company.
