A cybersecurity startup, IRIS C2, is actively seeking to acquire zero-day security vulnerabilities in popular software, dangling potential payouts of up to $7 million to attract top talent. However, the company’s operations are spearheaded by a duo with a well-documented history of far-right conspiracy theories, felony convictions, and fraudulent ventures, including the use of assumed names for fake intelligence companies and an AI-based lobbying platform. The X/Twitter account, IRIS C2 (@C2IRIS), launched in January 2025, has rapidly amassed over 4,000 followers by consistently posting about security vulnerabilities, artificial intelligence, and software exploits. The company, based in McLean, Virginia, purports to specialize in providing offensive cybersecurity capabilities.

A pinned post on the IRIS C2 X account articulates their business model: "Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience." The associated website, irisc2[.]com, reinforces this sentiment, detailing their acquisition of "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value." This aggressive recruitment strategy aims to tap into a pool of gifted but potentially uncredentialed individuals.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Government contracting portal G2Exchange.com identifies irisc2[.]com as being operated by Calvexa Group LLC, a Virginia-based entity. The contact domain for Calvexa Group, calvexagroup[.]com, redirects to irisc2[.]com. While Calvexa Group LLC is registered as a federal contractor, G2Exchange indicates no direct government contracts are currently active. The incorporation records for Calvexa Group LLC list an Arlington, Virginia address that is occupied by Jack Burkman, a 60-year-old founder and managing partner of the lobbying firm Burkman & Associates. When questioned about IRIS C2, Burkman deferred to his associate, 28-year-old Jacob Wohl.

Burkman and Wohl possess a significant and contentious history. They are known for fabricating intelligence firms to disseminate false narratives and frame public figures. Notable instances include fabricating sexual assault allegations against former FBI Director Robert Mueller and Pete Buttigieg, and falsely alleging extramarital affairs by Senator Elizabeth Warren and Kamala Harris during their presidential campaigns. Following the 2020 presidential election, both individuals faced prosecution in multiple U.S. states for orchestrating robocall schemes that disseminated misinformation about mail-in ballots, aiming to suppress votes in key battleground states. They were indicted on 15 felony counts in Cleveland for a robocall scheme targeting the Black vote in Detroit. In late 2025, after their appeals were rejected, they were sentenced to probation.

Further legal entanglements include a 2022 guilty plea by Wohl and Burkman to a single felony charge of telecommunications fraud in Ohio, resulting in a fine, probation, and community service. In March 2023, a New York civil court judge found they had violated federal and state civil rights laws, leading to a $1 million settlement. The Federal Communications Commission (FCC) imposed a substantial $5.1 million fine on Wohl and Burkman in June 2023 for their robocall activities, which at the time represented the FCC’s largest fine sought under the Telephone Consumer Protection Act.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Jacob Wohl’s entrepreneurial endeavors began early. By age 17, he had founded multiple investment firms and gained notoriety as the "Wohl of Wall Street" following appearances on Fox News discussing his hedge funds. In 2017, the Arizona Corporation Commission charged Wohl and his funds with 14 counts of securities fraud, ordering him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty to four felony counts of selling unregistered securities in California and received a two-year probation sentence.

The market for previously undisclosed security vulnerabilities is inherently diverse, attracting legitimate researchers, academics, opportunists, and those engaged in illicit cyber activities. However, the sector for selling offensive security services to the U.S. government typically operates with a higher degree of discretion. While numerous government contractors actively recruit vulnerability researchers and procure exclusive rights to novel software exploits, IRIS C2’s approach is notably audacious and public.

KrebsOnSecurity became aware of IRIS C2 last month after an attendee at a regional cybersecurity conference reported that Wohl and Calvexa Group were soliciting vulnerability research from attendees. In a direct interview with KrebsOnSecurity, Wohl stated that Jack Burkman is not involved in IRIS C2’s daily operations. Wohl explained that the company initially focused on penetration testing but has recently pivoted to offering phone-hacking services to government clients. He alluded to ongoing federal government contracts, but declined to provide specific details, citing confidentiality agreements.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Wohl admitted to having no formal education or training in computer science or information security, attributing his knowledge to self-study. He confidently asserted, "I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin." He described how security researchers regularly submit vulnerability findings, often in preliminary stages, requiring further development. "Let’s say someone finds a flaw in a media decoder on a phone," Wohl elaborated. "A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do."

Wohl claims IRIS C2 employs approximately 40 individuals, none of whom are permitted to list their employment on LinkedIn for operational security reasons. This clandestine operational posture mirrors past behavior. In September 2024, Politico reported that Burkman and Wohl were using pseudonyms – Wohl as "Jay Klein" and Burkman as "Bill Sanders" – to operate their defunct AI lobbying firm, LobbyMatic. Former employees resigned upon discovering their employers’ true identities, while others learned of the deception only after departing the company.

An update to this report on July 9th revealed that Burkman and Wohl were retained for $300,000 by a Canadian cryptocurrency fraudster wanted internationally for allegedly stealing $65 million from platforms like KyberSwap and Indexed Finance. According to journalist Molly White’s March 31 publication, Burkman and Wohl were engaged to pursue a "presidential pardon to avert a miscarriage of justice" for the accused hacker, who had not yet been convicted. This revelation further underscores the pattern of associating with questionable entities and engaging in ethically ambiguous activities, now transposed into the high-stakes realm of offensive cybersecurity.