From Political Sabotage to Cyber Espionage: The Dubious Rise of IRIS C2

In the shadowy world of vulnerability research—a high-stakes marketplace where software exploits can fetch seven-figure sums—a new player has emerged, promising "exquisite" offensive capabilities to the federal government. IRIS C2, a Virginia-based entity that burst onto the X (formerly Twitter) platform in January 2025, has been aggressively recruiting talent with the promise of million-dollar payouts. Yet, behind the slick marketing and the allure of top-tier cybersecurity work lies a far more controversial reality: the firm is the latest venture from Jack Burkman and Jacob Wohl, two notorious figures whose past is paved with felony convictions, fabricated intelligence operations, and a long history of deceptive business practices.

The Facade of Offensive Security

Since its inception, the IRIS C2 account (@C2IRIS) has garnered over 4,000 followers by positioning itself as an elite, results-oriented cybersecurity outfit. Operating out of McLean, Virginia, the firm purports to specialize in acquiring "zero-day exploits, individual primitives, partial chains, and full capabilities" across major software platforms. Their pitch to the research community is blunt: "We don’t care if they have a college degree or industry experience," provided they possess the "raw talent" required to dismantle modern software defenses.

The company’s website, irisc2[.]com, functions as a recruitment portal for this alleged digital arms trade, advertising payouts ranging from $10,000 to a staggering $7 million for verified exploits. On the surface, the business model mimics legitimate private sector vulnerability research firms that contract with intelligence and defense agencies. However, industry experts note that the brazen, public-facing nature of IRIS C2’s recruitment drive is highly anomalous in an industry that prizes extreme discretion and vetted, private channels.

A History of Deception: The Wohl-Burkman Chronicle

To understand the skepticism surrounding IRIS C2, one must look at the architects behind the venture. The government contracting portal G2Exchange identifies the operator of irisc2[.]com as Calvexa Group LLC. Incorporation records for the entity point to an address in Arlington, Virginia—the same base of operations for Jack Burkman, a 60-year-old political strategist and lobbyist known for his far-right conspiracy theories.

When confronted with the realities of the business, Burkman redirected all inquiries to his longtime associate, 28-year-old Jacob Wohl. The pair have spent the better part of a decade operating in the fringes of American politics, frequently using fake companies and pseudonyms to orchestrate disinformation campaigns.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Their track record includes:

  • Fabricated Scandals: In 2018 and 2019, the duo held press conferences promoting baseless sexual assault allegations against then-FBI Director Robert Mueller and Democratic presidential candidates, including Pete Buttigieg and Kamala Harris.
  • The Robocall Schemes: Following the 2020 election, the pair were indicted in Cleveland on 15 felony counts for an automated calling campaign designed to suppress Black voter turnout in Detroit. This culminated in a 2025 sentencing to probation.
  • Financial Fraud: Long before his pivot to political sabotage, Wohl was labeled the "Wohl of Wall Street" after claiming to run hedge funds at age 17. By 2017, the Arizona Corporation Commission charged him with 14 counts of securities fraud. He later pleaded guilty to four felony counts of selling unregistered securities in California.
  • Regulatory Penalties: In 2023, the Federal Communications Commission (FCC) hit the duo with a record-breaking $5.1 million fine for their illegal robocalling activities. That same year, a New York civil court judge ordered them to pay a $1 million settlement for violating federal and state civil rights laws.

The "LobbyMatic" Precedent

The transition to cybersecurity appears to be a direct evolution of their previous failed venture, "LobbyMatic." As reported by Politico in 2024, the pair attempted to market an AI-powered lobbying platform to major corporations. During that operation, Wohl allegedly adopted the pseudonym "Jay Klein," while Burkman operated as "Bill Sanders."

The facade eventually collapsed when employees discovered they were working for the notorious duo. Several staff members resigned immediately upon learning the true identities of their employers, highlighting a recurring pattern: the use of sophisticated, technology-based front companies to shield their involvement from potential clients and employees alike.

Inside the Operations of IRIS C2

In an interview with KrebsOnSecurity, Jacob Wohl claimed that while IRIS C2 began as a penetration testing firm, it had pivoted to "phone-hacking services" for the government. When asked for details regarding these alleged federal contracts, Wohl became evasive, citing the classified nature of his work.

Despite having no formal education in computer science or cybersecurity, Wohl maintains that his technical knowledge is self-taught and "exquisite." He claims the firm employs approximately 40 individuals, though he admitted that for "operational security reasons," none of these employees are permitted to list their employment on professional networks like LinkedIn.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Industry observers remain highly skeptical of these claims. The assertion that a firm run by two individuals with multiple felony convictions for fraud and civil rights violations would be trusted with sensitive national security-level exploits is, at best, improbable. Furthermore, the practice of requiring employees to remain anonymous—while ostensibly for "security"—mirrors the methods used during the LobbyMatic operation to prevent staff from uncovering the company’s true ownership.

Implications for the Cybersecurity Market

The existence of IRIS C2 raises significant concerns regarding the oversight of the vulnerability market. While the trade of exploits is a legitimate, albeit sensitive, industry, it relies heavily on trust, reputation, and stringent security clearances.

1. Risk to Researchers

For young, talented researchers who may be enticed by the promise of million-dollar payouts, the risks are substantial. Engaging with a firm led by individuals with a history of securities fraud and civil rights violations could result in more than just a missed paycheck. There is a tangible risk that research provided to the firm could be misused, exposed, or sold to adversarial actors, potentially leading to legal complications for the researchers themselves.

2. National Security Concerns

The federal government maintains strict requirements for contractors, particularly those dealing in "offensive" cyber capabilities. The fact that Calvexa Group LLC is registered as a federal contractor but lacks evidence of active, direct government contracts suggests a potential disconnect between their marketing claims and their actual operational status. If the firm is indeed attempting to penetrate the government contracting space, the lack of traditional vetting procedures for the individuals behind the company poses a profound security risk to any agency that might inadvertently engage with them.

3. Market Devaluation

The "colorful" nature of the vulnerability market—comprising academics, researchers, and gray-market brokers—is often characterized by a high degree of technical rigor. By introducing high-profile disinformation figures into this ecosystem, IRIS C2 risks polluting the professional environment. When entities with a history of fabrication start promising "head-spinning" capabilities, it undermines the credibility of legitimate firms operating in the same space.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Conclusion: A Pattern of Behavior

The transformation of Jacob Wohl and Jack Burkman from political provocateurs into "cybersecurity entrepreneurs" follows a predictable trajectory. By leveraging the buzzwords of the day—first AI lobbying, now zero-day exploits—the pair continues to seek out high-value, unregulated, or opaque markets where their penchant for deception can be masked behind a veneer of technical sophistication.

For the cybersecurity community, IRIS C2 serves as a cautionary tale. While the allure of significant financial reward is a powerful motivator, the professional risks associated with working for a company built on a foundation of felony fraud, pseudonym-based employment, and historical disinformation are non-trivial. As the firm continues to solicit researchers at conferences and online, the broader industry must remain vigilant, ensuring that the integrity of vulnerability research is not compromised by those who have spent their careers eroding the very concept of truth.

Related Posts

Digital Crackdown: U.S. Authorities Dismantle Massive Global Sports Piracy Network During World Cup 2026

The global stage of the FIFA World Cup 2026 was intended to be a celebration of athletic prowess and international unity. However, behind the scenes of the world’s most-watched sporting…

FBI Dismantles NetNut Proxy Network: A Major Blow to Global Cybercrime Infrastructure

In a landmark coordinated operation, the Federal Bureau of Investigation (FBI) has effectively crippled NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli technology firm Alarum Technologies [NASDAQ:…

You Missed

Bridging the Gap: HSMAI Calls for AI Pioneers at Fall 2024 Curate

  • By Nana
  • July 28, 2026
  • 3 views
Bridging the Gap: HSMAI Calls for AI Pioneers at Fall 2024 Curate

Shedding Light on Success: The Definitive Guide to Desk Lamps for the 2026 Academic Season

Shedding Light on Success: The Definitive Guide to Desk Lamps for the 2026 Academic Season

Shedding Light on Success: The Ultimate Guide to Professional Webcam Lighting for Students

  • By Asro
  • July 27, 2026
  • 3 views
Shedding Light on Success: The Ultimate Guide to Professional Webcam Lighting for Students

Asia Pacific Hospitality Sector Sees Significant Transactions and Strategic Developments

Asia Pacific Hospitality Sector Sees Significant Transactions and Strategic Developments

Residence Inn Boise West Unveils Transformative Renovation, Poised to Elevate Extended-Stay Experience in Dynamic Market

Residence Inn Boise West Unveils Transformative Renovation, Poised to Elevate Extended-Stay Experience in Dynamic Market

The Silent Engine of Hospitality: Transforming Hotel Housekeeping Through Digital Integration

The Silent Engine of Hospitality: Transforming Hotel Housekeeping Through Digital Integration