The High-Stakes World of IRIS C2: Cybersecurity or the Latest Act in a Long-Running Farce?

In the shadows of the cybersecurity industry—a sector traditionally defined by rigorous technical pedigree and extreme discretion—a new entity has emerged with the kind of brash, headline-grabbing marketing usually reserved for high-stakes venture capital or political smear campaigns. IRIS C2, a McLean, Virginia-based startup, is promising payouts of up to $7 million for "zero-day" software vulnerabilities. However, behind the slick facade and the promise of massive financial rewards for exploit developers lies a duo synonymous with some of the most notorious disinformation campaigns of the last decade: Jacob Wohl and Jack Burkman.

The Genesis of IRIS C2: A Digital Enigma

Since its inception in January 2025, the X (formerly Twitter) account @C2IRIS has cultivated a persona of cutting-edge offensive security. Positioning itself as a provider of "offensive cybersecurity capabilities," the firm claims to be an elite shop for the world’s most talented—and perhaps most anonymous—vulnerability researchers.

The company’s business model is explicitly predatory regarding talent acquisition. A pinned post on their social media feed candidly states: "We don’t care if they have a college degree/industry experience." Instead, they seek "junior engineers with raw talent/extremely high IQ."

The firm’s website, irisc2.com, serves as a digital storefront for the global trade of software exploits. It lists a tiered bounty structure for "zero-day exploits, individual primitives, partial chains, and full capabilities." Depending on the target, the reliability of the exploit, and its "operational value," the company claims it can authorize payments ranging from $10,000 to a staggering $7 million. For a firm that appears to have no verifiable history in the defense contracting sector, the audacity of these claims has left established industry professionals baffled.

Chronology of a Controversial Partnership

The trajectory of Wohl and Burkman is a well-documented saga of legal entanglements, fabricated intelligence, and political theater. Their transition from fringe political operatives to self-styled cybersecurity "titans" is merely the latest chapter in a long history of deceptive ventures.

Felons, Fraudsters Flog Offensive Cybersecurity Startup
  • 2015-2017: The Financial Mirage: Jacob Wohl, often dubbed "Wohl of Wall Street," burst onto the scene as a teenage hedge fund prodigy. This ended in 2017 when the Arizona Corporation Commission charged him with 14 counts of securities fraud.
  • 2019: The Fabrication Era: The duo gained national infamy for orchestrating a series of fake intelligence operations. They were linked to fabricated sexual assault allegations against then-FBI Director Robert Mueller and Democratic presidential candidate Pete Buttigieg.
  • 2020: The Robocall Indictment: During the 2020 election cycle, the pair engaged in a massive robocall campaign targeting voters in battleground states. This culminated in 15 felony counts in Ohio, focused on efforts to suppress the Black vote in Detroit.
  • 2023: The FCC Hammer: The Federal Communications Commission (FCC) hit the duo with a $5.1 million fine—the largest of its kind—for their illegal robocalling activities.
  • 2024: The AI Lobbying Charade: As reported by Politico, the pair operated a defunct AI-lobbying firm called "LobbyMatic" under assumed names ("Jay Klein" and "Bill Sanders"). Employees were left stunned when they discovered the true identities of their bosses.
  • 2025: The Cybersecurity Pivot: Having exhausted the political and lobbying spheres, Wohl and Burkman have now rebranded as IRIS C2, pivoting to the lucrative, murky world of zero-day vulnerability acquisition.

Supporting Data: The "Calvexa" Connection

Public records reveal that IRIS C2 is operated by a business entity known as Calvexa Group LLC. While Calvexa is registered as a federal contractor, the government contracting portal G2Exchange indicates that the company currently holds no active, direct government contracts.

The physical address associated with Calvexa Group leads directly to a property occupied by Jack Burkman’s lobbying firm, Burkman & Associates. When reached for comment, Burkman deferred all inquiries to Wohl, signaling a familiar dynamic where the two share resources and operational infrastructure while maintaining a facade of professional independence.

The technical claims made by IRIS C2 are equally suspect. Wohl, who admits to having no formal computer science education, insists he is self-taught and possesses "exquisite" technical capabilities. Yet, researchers and industry observers find little evidence to support these claims. The company’s operations appear to be a "middleman" service—recruiting researchers to find raw, unrefined exploit primitives and attempting to polish them for resale to, presumably, government entities or intelligence agencies.

Implications for the Cybersecurity Market

The rise of IRIS C2 poses a significant dilemma for the cybersecurity community. The "zero-day" market—the buying and selling of software vulnerabilities that remain unknown to the original software vendor—is inherently opaque. It is a world populated by nation-states, security researchers, and private intelligence contractors.

However, industry standards for such firms typically involve rigorous background checks, secure facilities, and a track record of transparency with oversight bodies. IRIS C2 ignores these norms. By operating with a "no questions asked" recruitment policy and a history of deception, the firm threatens to destabilize the trust that is essential for responsible vulnerability disclosure.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Furthermore, the recent revelation by journalist Molly White—that the pair was hired by a fugitive cryptocurrency hacker to lobby for a presidential pardon—suggests that IRIS C2 may be less interested in national security and more interested in leveraging the "hacker" identity for high-fee legal and political interference.

Official Responses and Industry Skepticism

In interviews, Jacob Wohl maintains a defensive and boastful posture. He claims the company employs 40 people, none of whom are permitted to list their employment on LinkedIn for "operational security reasons." This secrecy, however, is a double-edged sword; it prevents any verification of the company’s actual capabilities while shielding the employees from knowing the true nature of their employer.

When pressed on his lack of formal training, Wohl retorted, "I know more about tech than anyone." He dismisses his past legal troubles as political persecution, a narrative he has maintained since his first brushes with the law in 2017.

Industry experts remain deeply skeptical. "In the cybersecurity space, your reputation is your currency," says one independent security consultant who requested anonymity. "You cannot simply pivot from running fake robocalls to handling high-level exploits. The ‘bad actors’ in the vulnerability market are usually professionals, not performance artists. The risk here isn’t just that the company is a scam—it’s that they are handling sensitive code without the professional maturity to prevent it from leaking or being misused."

A Dangerous Precedent

The existence of IRIS C2 serves as a cautionary tale regarding the "democratization" of cyber-weaponry. As the barrier to entry for acquiring powerful software exploits lowers, the potential for bad-faith actors to profit from that trade grows exponentially.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Whether IRIS C2 is a legitimate (albeit eccentric) player or merely the latest "shell" for a pair of serial grifters, the implications remain severe. If they are successfully collecting and selling vulnerabilities, they are participating in a market that could have catastrophic consequences for global digital infrastructure. If they are not, they are still creating a dangerous environment that exploits young, talented researchers by pulling them into a network associated with fraud, felony convictions, and federal investigations.

As the cybersecurity community continues to monitor the situation, the case of IRIS C2 serves as a stark reminder: in the digital age, a slick website and a million-dollar offer are not evidence of capability—they are, in the case of Wohl and Burkman, often the most significant red flags of all.

Related Posts

Digital Crackdown: U.S. Authorities Dismantle Massive Global Sports Piracy Network During World Cup 2026

The global stage of the FIFA World Cup 2026 was intended to be a celebration of athletic prowess and international unity. However, behind the scenes of the world’s most-watched sporting…

FBI Dismantles NetNut Proxy Network: A Major Blow to Global Cybercrime Infrastructure

In a landmark coordinated operation, the Federal Bureau of Investigation (FBI) has effectively crippled NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli technology firm Alarum Technologies [NASDAQ:…

You Missed

Bridging the Gap: HSMAI Calls for AI Pioneers at Fall 2024 Curate

  • By Nana
  • July 28, 2026
  • 2 views
Bridging the Gap: HSMAI Calls for AI Pioneers at Fall 2024 Curate

Shedding Light on Success: The Definitive Guide to Desk Lamps for the 2026 Academic Season

Shedding Light on Success: The Definitive Guide to Desk Lamps for the 2026 Academic Season

Shedding Light on Success: The Ultimate Guide to Professional Webcam Lighting for Students

  • By Asro
  • July 27, 2026
  • 2 views
Shedding Light on Success: The Ultimate Guide to Professional Webcam Lighting for Students

Asia Pacific Hospitality Sector Sees Significant Transactions and Strategic Developments

Asia Pacific Hospitality Sector Sees Significant Transactions and Strategic Developments

Residence Inn Boise West Unveils Transformative Renovation, Poised to Elevate Extended-Stay Experience in Dynamic Market

Residence Inn Boise West Unveils Transformative Renovation, Poised to Elevate Extended-Stay Experience in Dynamic Market

The Silent Engine of Hospitality: Transforming Hotel Housekeeping Through Digital Integration

The Silent Engine of Hospitality: Transforming Hotel Housekeeping Through Digital Integration