From Political Sabotage to Cyber Espionage: The Troubling Rise of IRIS C2

from-political-sabotage-to-cyber-espionage-the-troubling-rise-of-iris-c2

In the shadowy world of vulnerability research—a high-stakes marketplace where software "zero-day" exploits can command millions of dollars—reputation is usually the only currency that matters. It is a domain typically populated by disciplined academics, clandestine government contractors, and highly vetted security professionals. However, a new player has emerged in McLean, Virginia, that defies every industry norm.

IRIS C2, a startup promising multi-million dollar payouts for offensive software exploits, is the latest venture from two of the most notorious figures in modern American political disinformation: Jack Burkman and Jacob Wohl. Their pivot from failed lobbying platforms and discredited intelligence operations to the sensitive, high-security world of national cyber warfare has sent shockwaves through the cybersecurity community, raising urgent questions about the lack of oversight in the procurement of digital weapons.

The Genesis of IRIS C2: A Digital Shell Game

Since January 2025, the X (formerly Twitter) account @C2IRIS has been aggressively marketing its services, claiming to specialize in offensive cybersecurity capabilities. With over 4,000 followers, the account frequently shares technical banter regarding AI-driven exploits and software vulnerabilities.

The company’s business model is explicitly outlined in a pinned post: "Attract the very best vulnerability researchers and exploit developers in the world to join our company… We don’t care if they have a college degree/industry experience."

While the tone is framed as meritocratic, the reality behind the corporate veil is far more opaque. According to records from the government contracting portal G2Exchange, the website irisc2[.]com is operated by Calvexa Group LLC. Despite being registered as a federal contractor, the company shows no evidence of holding active, legitimate government contracts. When visitors attempt to contact Calvexa Group via its official site, they are redirected to the IRIS C2 storefront.

The registered address for Calvexa Group in Arlington, Virginia, traces back to the offices of Jack Burkman, a 60-year-old lobbyist with a long history of controversial political maneuvering. When contacted regarding the nature of IRIS C2’s operations, Burkman deferred all questions to his long-term associate, 28-year-old Jacob Wohl.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A History of Deception: A Chronological Overview

To understand the skepticism with which the cybersecurity community views IRIS C2, one must examine the track record of its founders. The duo’s history is a recurring cycle of grandiose claims, fake personas, and legal entanglement.

2015–2017: The "Wohl of Wall Street"

Jacob Wohl first gained notoriety as a teenager, appearing on Fox News to promote hedge funds he claimed to manage. This venture ended in 2017 when the Arizona Corporation Commission charged him with 14 counts of securities fraud, eventually resulting in a $35,000 restitution order.

2019–2020: Political Sabotage

Wohl and Burkman became household names for orchestrating elaborate, defamatory campaigns against public figures. They were responsible for fabricated sexual assault allegations against then-FBI Director Robert Mueller and Pete Buttigieg, as well as baseless rumors regarding the personal lives of Senator Elizabeth Warren and then-candidate Kamala Harris.

2021–2023: The Robocall Era and Legal Reckoning

Following the 2020 election, the duo launched a massive robocall campaign targeting voters in battleground states with disinformation regarding mail-in ballots. The fallout was swift and severe:

  • 2022: Both men pleaded guilty to felony telecommunications fraud in Ohio, resulting in fines, probation, and community service.
  • 2023: A New York court ordered the pair to pay a $1 million settlement for violating federal and state civil rights laws.
  • 2023: The Federal Communications Commission (FCC) issued a record-breaking $5.1 million fine against them, the largest ever sought under the Telephone Consumer Protection Act.
  • 2025: The pair was sentenced to probation after being indicted on 15 felony counts in Cleveland related to a vote-suppression scheme targeting Detroit.

2024–Present: The Pivot to "AI Lobbying" and Cyber Warfare

In late 2024, Politico exposed their "LobbyMatic" venture, an AI-based lobbying platform where the pair operated under aliases—Wohl as "Jay Klein" and Burkman as "Bill Sanders." The company collapsed after employees discovered their true identities. By 2025, the pair had re-emerged as leaders of IRIS C2, pivoting from political disinformation to the acquisition of cyber weapons.

Supporting Data: The Illusion of Technical Expertise

During an interview with KrebsOnSecurity, Jacob Wohl claimed that IRIS C2 currently employs 40 individuals. However, he admitted that none of these employees are permitted to list their employment on professional platforms like LinkedIn for "operational security."

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Wohl, who lacks any formal education or technical background in computer science, insisted upon his own expertise during the interview. "I know more about tech than anyone," Wohl stated. "My background has always been extremely technical… I’ve always been deeply into tech."

These claims are difficult to reconcile with the reality of their previous business ventures. Security researchers who have interacted with the pair report that they often present "preliminary" or "half-baked" findings, seeking to outsource the actual labor of refining these exploits into stable, weaponized capabilities.

Furthermore, reports from journalist Molly White highlight that the duo’s business interests remain as questionable as ever. In 2026, it was revealed that Wohl and Burkman accepted a $300,000 retainer from a fugitive cryptocurrency hacker—wanted for a $65 million theft—to lobby for a presidential pardon. This suggests that IRIS C2 may be less of a legitimate security firm and more of a front for high-risk, legally precarious services.

Implications for the Cybersecurity Industry

The emergence of IRIS C2 highlights a dangerous blind spot in the vulnerability market. While legitimate firms like ZDI or companies that provide exploit research to government agencies operate under strict compliance, ethical, and legal frameworks, the barrier to entry for "offensive security" is alarmingly low.

The Normalization of Private Exploits

The market for zero-day vulnerabilities—software flaws that are unknown to the vendor—is effectively the "arms trade" of the digital age. When individuals with a history of fraud and political sabotage gain access to these tools, the risk of them falling into the hands of foreign intelligence services, criminal cartels, or other bad actors increases exponentially.

The Reputation Risk to Researchers

The cybersecurity industry thrives on collaboration and trust. When individuals like Wohl and Burkman pester researchers at conferences to buy their findings, they poison the well of professional cooperation. Many in the industry worry that such firms could lure junior developers—who may be financially desperate or naive to the founders’ pasts—into compromising their own professional reputations or, worse, becoming accessories to illegal activity.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Regulatory Deficiencies

The fact that a company like Calvexa Group can register as a federal contractor while being run by convicted felons suggests a failure in the vetting process for government contractors. While the duo currently lacks direct government contracts, their ability to navigate these systems remains a point of contention for those who advocate for stronger oversight of the private cybersecurity sector.

Conclusion: A Warning to the Market

As of mid-2026, IRIS C2 continues to solicit talent via social media, promising astronomical payouts for exploits that could theoretically compromise millions of devices. Yet, the evidence suggests that the company is built on the same foundations of deceit and manipulation that defined the founders’ previous failed ventures.

For the cybersecurity community, the rise of IRIS C2 serves as a grim reminder that as the demand for digital weapons grows, so too does the opportunity for bad actors to capitalize on that demand. Industry professionals are urged to exercise extreme caution when engaging with entities that lack transparency, professional standing, and a verifiable history of ethical conduct. In the world of high-stakes exploits, the greatest threat may not just be the code itself, but the individuals who seek to control it.