A cybersecurity startup, which is actively soliciting millions of dollars for the acquisition of zero-day security vulnerabilities in widely used software, is reportedly helmed by a pair of convicted felons and far-right conspiracy theorists. Their prior entrepreneurial endeavors include the creation of fraudulent intelligence companies and a now-defunct AI-powered lobbying platform, both of which were operated under assumed identities. This exposé delves into the murky origins and questionable operations of IRIS C2, a company that, despite its ambitious claims, is shrouded in a history of deception and legal entanglements.
The entity known as IRIS C2, operating under the X/Twitter handle @C2IRIS, has rapidly amassed a following of over 4,000 users since its inception in January 2025. Its prolific output on the platform centers on security vulnerabilities, artificial intelligence, and software exploits. IRIS C2 purports to be a cybersecurity firm based in McLean, Virginia, specializing in the provision of offensive cybersecurity capabilities. A pinned post on its X account boldly outlines its business strategy: "Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience.” This recruitment approach, deliberately bypassing traditional qualifications, hints at a desire to tap into a less scrutinized talent pool.
The company’s website, irisc2[.]com, reinforces this recruitment drive by advertising numerous open positions. A recent LinkedIn post from IRIS C2 boasted an overwhelming volume of applications, suggesting significant interest from potential employees. The website boldly claims IRIS C2’s business model involves acquiring "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value." The prospect of such substantial financial rewards is undoubtedly a potent lure for vulnerability researchers.
Further investigation into IRIS C2’s corporate structure reveals that the domain irisc2[.]com is operated by a Virginia-based entity named Calvexa Group LLC, according to the government contracting portal g2exchange.com. The "contact" link on the Calvexa Group website, calvexagroup[.]com, redirects directly to irisc2[.]com, indicating a close operational link. While G2Exchange lists Calvexa Group LLC as a registered federal contractor, it appears to have no direct government contracts to its name.

The registered address for Calvexa Group LLC in Arlington, Virginia, is a property associated with Jack Burkman, a 60-year-old founder and managing partner of the lobbying firm Burkman & Associates. When questioned about IRIS C2, Burkman deferred inquiries to his long-time associate, 28-year-old Jacob Wohl. This referral immediately raises a red flag, given the documented history of both Burkman and Wohl.
Burkman and Wohl possess a well-documented and often notorious history of engaging in deceptive practices. Their past activities include the establishment of fabricated intelligence companies used to disseminate false narratives and frame public figures. This has encompassed the fabrication of sexual assault allegations against former FBI Director Robert Mueller and Pete Buttigieg, who was then the Mayor of South Bend, Indiana, and a Democratic presidential candidate. In 2019, Burkman and Wohl held press conferences making unsubstantiated claims of extramarital affairs involving Senator Elizabeth Warren (D-Mass.) and Kamala Harris, a candidate for the presidency in 2020.
Following the 2020 presidential election, Wohl and Burkman faced prosecution in multiple U.S. states for their involvement in a robocall scheme. Thousands of robocalls were made to residents in battleground states, disseminating false information about mail-in ballots. They were indicted in Cleveland on 15 felony counts related to orchestrating a robocall campaign designed to suppress the Black vote in Detroit. In late 2025, after their appeals to dismiss the charges were rejected, they were sentenced to probation.
Adding to their legal troubles, in 2022, both Wohl and Burkman pleaded guilty to a single felony charge of telecommunications fraud in Ohio, receiving a fine, probation, and community service as penalties. Subsequently, in March 2023, a judge in a New York civil case ruled that Wohl and Burkman had violated federal and state civil rights laws, leading to a $1 million settlement. The Federal Communications Commission (FCC) further imposed a $5.1 million fine against Wohl and Burkman in June 2023 for their robocall campaigns. At the time, this represented the largest fine ever sought by the FCC under the Telephone Consumer Protection Act, underscoring the severity of their actions.
Jacob Wohl’s history also includes significant financial improprieties. By the age of 17, he had already founded multiple investment firms, earning the moniker "Wohl of Wall Street" after appearing on Fox News in 2015 to discuss his burgeoning hedge funds. However, in 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, ordering him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities, receiving a two-year probation sentence.

The market for previously unknown security vulnerabilities, often referred to as zero-day exploits, has historically attracted a diverse array of individuals. This spectrum ranges from legitimate researchers and academics to charlatans, individuals seeking notoriety, and those actively involved in cybercrime. However, the segment of this market focused on selling offensive security services to the U.S. government typically operates with a far greater degree of discretion. While numerous government contractors engage in recruiting vulnerability researchers and securing exclusive rights to novel software exploits, none have adopted the overtly brazen and public approach exemplified by IRIS C2.
KrebsOnSecurity became aware of IRIS C2 only last month, following a report from an attendee at a regional cybersecurity conference who noted that Wohl and Calvexa Group were actively soliciting vulnerability research from attendees.
In an interview with KrebsOnSecurity, Wohl asserted that Jack Burkman is not involved in the daily operations of IRIS C2. Wohl stated that IRIS C2 initially functioned as a penetration testing company but recently shifted its focus to providing phone-hacking services to the government. Throughout the interview, Wohl repeatedly alluded to working on federal government contracts but declined to provide specific details, citing a lack of authorization to discuss them publicly.
Wohl admitted to lacking formal education or training in computer science or information security, attributing his expertise to self-teaching. He confidently declared, "I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin." This assertion, made by an individual with a history of fraudulent activities, warrants significant skepticism.
Wohl claimed that security researchers submit unique vulnerability findings to IRIS C2 "on a regular basis." However, he characterized many of these submissions as preliminary and lacking in complete execution. He elaborated with an example: "Let’s say someone finds a flaw in a media decoder on a phone. A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do." This suggests IRIS C2 positions itself as a company that refines and operationalizes raw vulnerability findings.

Wohl stated that IRIS C2 employs approximately 40 individuals, though he indicated that none are permitted to list their employment on LinkedIn for operational security reasons. This lack of transparency is consistent with the company’s overall clandestine approach. An earlier post from the IRIS C2 X account suggested that the author’s girlfriend was unaware of his professional activities, hinting at a broader culture of secrecy. If IRIS C2 has other employees, they too might be unaware of Wohl’s extensive history of fabrications or even his true identity.
Adding another layer of deception, Politico reported in September 2024 that Burkman and Wohl were boasting about substantial business dealings with major companies for their now-defunct company, LobbyMatic. This firm purported to leverage artificial intelligence for political lobbying efforts. However, Politico uncovered that the pair operated LobbyMatic under pseudonyms, with Wohl reportedly using "Jay Klein" and Burkman adopting the moniker "Bill Sanders." Politico’s investigation revealed that two former LobbyMatic employees resigned upon discovering their employers’ true identities, while others only learned the truth after their departure.
In a significant update, several readers brought to light a March 31 publication by journalist Molly White. This report detailed that Burkman and Wohl received a $300,000 retainer from a Canadian cryptocurrency fraudster who is a person of interest to the United States and several other countries. This individual is accused of stealing $65 million from crypto platforms KyberSwap and Indexed Finance. According to White’s report, Burkman and Wohl were hired to pursue a "presidential pardon to avert a miscarriage of justice" on behalf of the accused hacker, who has not yet been convicted of any crimes. This latest revelation further solidifies the pattern of association with individuals involved in illicit financial activities and raises serious questions about the ethical underpinnings and ultimate objectives of IRIS C2 and its leadership. The confluence of convicted felons, history of fraud, and the pursuit of high-stakes cybersecurity capabilities creates a deeply concerning picture of the company’s operations and its potential impact on national security.

