Far-Right Conspiracy Theorists and Convicted Felons Linked to Cybersecurity Startup Soliciting Millions for Zero-Day Vulnerabilities

A burgeoning cybersecurity startup, IRIS C2, which is aggressively marketing itself as a buyer of high-value zero-day security vulnerabilities with the promise of multi-million dollar payouts, is reportedly helmed by a duo with a documented history of far-right conspiracy theories, felony convictions, and a penchant for operating under assumed identities. The company’s recent emergence onto the cybersecurity landscape, actively recruiting top-tier exploit developers and vulnerability researchers, has raised significant red flags due to the past activities of its purported leaders, Jack Burkman and Jacob Wohl.
IRIS C2, operating under the X/Twitter handle @C2IRIS and a website at irisc2[.]com, has garnered over 4,000 followers since its inception in January 2025. The account frequently publishes content related to security vulnerabilities, artificial intelligence, and software exploits, positioning itself as a provider of offensive cybersecurity capabilities. The company’s recruitment strategy, prominently displayed on its X profile, explicitly targets "the very best vulnerability researchers and exploit developers in the world," emphasizing raw talent and high IQ over formal education or industry experience. Payouts for acquired exploits are advertised to range from $10,000 to an astonishing $7 million, contingent upon the target, reliability, and operational value of the vulnerability.
Calvexa Group LLC: The Corporate Facade
Government contracting portal G2Exchange.com identifies irisc2[.]com as being operated by Calvexa Group LLC, a Virginia-based entity. Further investigation reveals that the contact link for Calvexa Group, calvexagroup[.]com, redirects directly to the IRIS C2 website, suggesting a deep integration between the two entities. While Calvexa Group LLC is registered as a federal contractor, G2Exchange records indicate no active direct government contracts for the company.
The registered address for Calvexa Group LLC in Arlington, Virginia, is notably occupied by Jack Burkman, a 60-year-old figure known for founding the lobbying firm Burkman & Associates. When questioned about IRIS C2, Burkman reportedly deferred inquiries to his long-time associate, 28-year-old Jacob Wohl.

A Pattern of Deception and Legal Troubles
Burkman and Wohl share a well-documented history marked by the creation of fictitious intelligence firms and the propagation of false narratives aimed at discrediting public figures. Their past endeavors include fabricating sexual assault allegations against former FBI Director Robert Mueller and Pete Buttigieg, who was then Mayor of South Bend, Indiana, and a Democratic presidential candidate. In 2019, Burkman and Wohl held press conferences making unsubstantiated claims of extramarital affairs involving Senator Elizabeth Warren (D-Mass.) and Kamala Harris, then a leading candidate for the 2020 Democratic presidential nomination.
The duo’s controversial activities extended to the 2020 presidential election. Wohl and Burkman faced prosecution in multiple U.S. states for orchestrating a widespread robocall scheme targeting residents of battleground states. The campaign disseminated false information regarding mail-in ballots, aiming to suppress voter turnout. In Cleveland, they were indicted on 15 felony counts related to this scheme, specifically targeting Black voters in Detroit. In late 2025, following the rejection of their appeals to dismiss the charges, they were sentenced to probation.
Further legal entanglements include a guilty plea by both Wohl and Burkman in 2022 to a single felony charge of telecommunications fraud in Ohio, resulting in a fine, probation, and community service. In March 2023, a New York civil court ruled that Wohl and Burkman had violated federal and state civil rights laws, leading to a $1 million settlement. The Federal Communications Commission (FCC) took significant action in June 2023, imposing a $5.1 million fine against Wohl and Burkman for their robocall campaigns. At the time, this represented the largest fine ever sought by the FCC under the Telephone Consumer Protection Act, underscoring the severity of their violations.
Wohl’s Entrepreneurial Ambitions and Securities Fraud Charges
Jacob Wohl’s early career was characterized by ambitious ventures. By the age of 17, he had established multiple investment firms, earning the moniker "Wohl of Wall Street" after appearing on Fox News in 2015 to discuss his nascent hedge funds. However, these early successes were overshadowed by legal repercussions. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, ultimately ordering him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities, receiving a two-year probation sentence.
IRIS C2’s Offensive Cybersecurity Ambitions
The market for previously undiscovered security vulnerabilities, often referred to as zero-day exploits, is a complex ecosystem. It typically comprises legitimate researchers, academics, ethical hackers, and unfortunately, individuals involved in cybercrime. While many government contractors actively engage with vulnerability researchers and acquire novel software exploits, the overt and aggressive solicitation tactics employed by IRIS C2 are unusual within this sector.

KrebsOnSecurity became aware of IRIS C2’s activities when an attendee at a regional cybersecurity conference reported that Wohl and Calvexa Group were actively approaching individuals about acquiring their vulnerability research.
In an interview with KrebsOnSecurity, Wohl stated that Jack Burkman was not involved in the daily operations of IRIS C2. He explained that the company initially focused on penetration testing but recently pivoted to offering phone-hacking services to government clients. Throughout the conversation, Wohl alluded to working on federal government contracts, though he declined to provide specific details, citing confidentiality agreements.
Wohl admitted to lacking formal education or training in computer science or information security, asserting that his expertise is largely self-taught. He confidently stated, "I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."
Wohl described the inflow of vulnerability findings from security researchers as regular, but often preliminary. He elaborated, "Let’s say someone finds a flaw in a media decoder on a phone. A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do."
IRIS C2 claims to employ approximately 40 individuals, although Wohl stated that none are permitted to publicly disclose their employment on platforms like LinkedIn due to operational security concerns. This secrecy extends to the broader workforce, as employees might be unaware of Wohl’s past fabrications or even his true identity.

Operating Under Pseudonyms: The LobbyMatic Precedent
The use of assumed names by Wohl and Burkman is not unprecedented. In September 2024, Politico reported that the pair had been promoting their now-defunct company, LobbyMatic, which purported to leverage artificial intelligence for political lobbying. However, Politico’s investigation revealed that Wohl and Burkman operated LobbyMatic using pseudonyms, with Wohl reportedly adopting the name "Jay Klein" and Burkman using "Bill Sanders." Politico further reported that at least two former LobbyMatic employees resigned after discovering the true identities of their employers, while others only learned of the deception after their departure.
Allegations of Representing a Cryptocurrency Fraudster
An update to this developing story highlights a potentially significant aspect of Burkman and Wohl’s recent activities. A March 31 publication by journalist Molly White brought attention to reports that Burkman and Wohl received a $300,000 retainer from a Canadian national wanted by the United States and several other countries for allegedly orchestrating a cryptocurrency fraud scheme that defrauded platforms like KyberSwap and Indexed Finance of an estimated $65 million. According to White’s report, Burkman and Wohl were hired to pursue a "presidential pardon to avert a miscarriage of justice" on behalf of the accused hacker, who at the time of the report had not yet been convicted. This engagement, if accurate, further complicates the ethical landscape surrounding IRIS C2’s operations and its potential clientele.
Implications for the Cybersecurity Landscape
The emergence of IRIS C2, led by individuals with such a contentious history, raises several critical questions for the cybersecurity industry and government agencies. The aggressive pursuit of zero-day vulnerabilities, particularly by entities with questionable backgrounds, poses inherent risks. Such vulnerabilities, when acquired by private actors, could potentially be weaponized or fall into the wrong hands, undermining national security and the integrity of digital infrastructure.
The recruitment strategy of IRIS C2, appealing to young, talented individuals, may also be seen as exploiting a talent pool that is eager for recognition and financial reward. The lack of transparency surrounding their operations and the potential for undisclosed affiliations with foreign governments or illicit actors are significant concerns.
The cybersecurity market is indeed a complex arena, attracting a diverse range of participants. However, the case of IRIS C2 underscores the critical need for thorough due diligence and robust vetting processes for companies operating within the sensitive domain of offensive cybersecurity, especially when engaging with government entities. The long-term implications of such ventures, particularly those led by individuals with a history of deception and legal challenges, warrant close scrutiny from regulators, law enforcement, and the broader cybersecurity community. The potential for such exploits to be misused, intentionally or unintentionally, remains a pressing concern as IRIS C2 continues to build its presence in the lucrative, yet shadowy, market for zero-day vulnerabilities.







