A new cybersecurity startup, IRIS C2, is actively recruiting top-tier vulnerability researchers and exploit developers by promising potentially million-dollar payouts for zero-day security vulnerabilities in popular software. However, a deep dive by KrebsOnSecurity reveals that this ambitious venture is helmed by a duo with a notorious history of far-right conspiracy theories, felony convictions, and a penchant for operating under assumed identities. Their previous endeavors include the creation of fictitious intelligence firms and a defunct AI-powered lobbying platform, casting a significant shadow of doubt over the legitimacy and ethical underpinnings of IRIS C2.

IRIS C2, which operates under the X/Twitter handle @C2IRIS and claims to be based in McLean, Virginia, has rapidly amassed over 4,000 followers since its inception in January 2025. The account is a constant stream of posts concerning security vulnerabilities, artificial intelligence, and software exploits. The company’s stated business model, prominently featured in a pinned post on their X account, is to "attract the very best vulnerability researchers and exploit developers in the world to join our company." They emphasize a focus on "junior engineers with raw talent/extremely high IQ," explicitly stating that a college degree or industry experience is not a prerequisite.

The website linked to the IRIS C2 profile, irisc2[.]com, mirrors this recruitment drive, advertising numerous open positions and boasting about an overwhelming number of applications received. The site boldly states that IRIS C2 is in the business of acquiring "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms." The advertised payouts are staggering, ranging from $10,000 to a remarkable $7 million, contingent on the exploit’s target, reliability, and operational value. This aggressive, public-facing approach to acquiring such sensitive cyber capabilities is highly unusual within the typically more discreet government contracting space.

Further investigation through the government contracting portal g2exchange.com reveals that irisc2[.]com is operated by Calvexa Group LLC, a Virginia-based entity. The contact link for Calvexa Group, calvexagroup[.]com, redirects directly to the IRIS C2 website, creating a clear operational nexus. While Calvexa Group LLC is registered as a federal contractor, it does not appear to be engaged in any direct government contracts, according to G2Exchange.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

The Arlington, Virginia address listed in Calvexa Group LLC’s incorporation records is associated with Jack Burkman, the 60-year-old founder and managing partner of the lobbying firm Burkman & Associates. When questioned about IRIS C2, Burkman deferred inquiries to his long-time associate, 28-year-old Jacob Wohl.

Burkman and Wohl share a well-documented and controversial history. They are known for fabricating intelligence companies to disseminate false narratives and frame public figures. This includes the creation of fabricated sexual assault allegations against former FBI Director Robert Mueller and Pete Buttigieg, who was then the mayor of South Bend, Indiana, and a Democratic presidential candidate. In 2019, Burkman and Wohl held press conferences making baseless claims of extramarital affairs by Senator Elizabeth Warren (D-Mass.) and Kamala Harris, who was a 2020 presidential candidate.

Following the 2020 presidential election, Wohl and Burkman faced prosecution in multiple U.S. states for orchestrating a widespread robocall scheme. They disseminated false information about mail-in ballots to residents of crucial swing states. In Cleveland, they were indicted on 15 felony counts for their role in a robocall operation designed to suppress the Black vote in Detroit. After their appeals to dismiss the charges were unsuccessful, they were sentenced to probation in late 2025.

Adding to their legal troubles, Wohl and Burkman pleaded guilty to a single felony charge of telecommunications fraud in Ohio in 2022. Their sentence included a fine, probation, and community service. In March 2023, a New York civil court judge ruled that the pair had violated federal and state civil rights laws, leading to a $1 million settlement. The Federal Communications Commission (FCC) further penalized Wohl and Burkman in June 2023, imposing a $5.1 million fine for their robocall campaigns. At the time, this was the largest fine ever sought by the FCC under the Telephone Consumer Protection Act.

Jacob Wohl’s entrepreneurial endeavors began at a young age, and by 17, he had launched multiple investment firms. He gained media attention, even appearing on Fox News in 2015 to discuss his hedge funds, earning him the moniker "Wohl of Wall Street." However, his financial ventures were not without controversy. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, ordering him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities and received a two-year probation sentence.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

The market for previously unknown security vulnerabilities, often referred to as the "bug bounty" or exploit acquisition market, has historically attracted a diverse group of individuals, including legitimate researchers, academics, opportunists, and those involved in cybercriminal activities. However, the market for selling offensive security services, particularly to government entities, generally operates with a greater degree of discretion. While many established government contractors actively engage vulnerability researchers and acquire exclusive rights to novel software exploits, IRIS C2’s overtly public and aggressive approach stands in stark contrast.

KrebsOnSecurity first became aware of IRIS C2 last month when an attendee at a regional cybersecurity conference reported that Wohl and Calvexa Group were actively approaching individuals to solicit their vulnerability research.

In a recent interview with KrebsOnSecurity, Wohl asserted that Jack Burkman is not involved in the day-to-day operations of IRIS C2. Wohl stated that the company initially focused on penetration testing but recently pivoted to offering phone-hacking services to government clients. He repeatedly alluded to working on federal government contracts but declined to provide specific details, citing confidentiality restrictions.

Wohl admitted to having no formal education or training in computer science or information security, attributing his knowledge to self-teaching. He boasted about his technical acumen, claiming, "I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."

According to Wohl, IRIS C2 regularly receives unique vulnerability findings from security researchers. However, he characterized many of these submissions as preliminary, requiring further development. He elaborated, "Let’s say someone finds a flaw in a media decoder on a phone. A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do."

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Wohl claimed IRIS C2 employs approximately 40 individuals, although he stated that none are permitted to list their employment on LinkedIn for operational security reasons. This echoes a sentiment expressed in May by the author of the IRIS C2 X account, who noted his girlfriend was unaware of his profession. If IRIS C2 indeed has other employees, they may be equally uninformed about Wohl’s history of fabrications and potentially his true identity.

Further complicating the narrative, Politico reported in September 2024 that Burkman and Wohl were promoting their now-defunct company, LobbyMatic, which purportedly utilized artificial intelligence for political lobbying efforts. Politico discovered that the pair operated the company under pseudonyms, with Wohl reportedly using "Jay Klein" and Burkman adopting the moniker "Bill Sanders." The report indicated that two former LobbyMatic employees resigned upon learning their employers’ true identities, while others only discovered the deception after their departure.

An update on July 9th highlighted a March 31 publication by journalist Molly White, which revealed that Burkman and Wohl received a $300,000 retainer from a Canadian cryptocurrency fraudster wanted by the United States and other countries for allegedly stealing $65 million from platforms KyberSwap and Indexed Finance. According to White’s report, Burkman and Wohl were hired to pursue a "presidential pardon to avert a miscarriage of justice" on behalf of the accused hacker, who has not yet been convicted. This revelation further underscores the questionable associations and alleged improprieties linked to the individuals behind IRIS C2.