The Shadowy Rise of IRIS C2: Cybersecurity’s Most Controversial New Player
In the high-stakes world of zero-day vulnerability acquisition—a shadowy marketplace where software exploits can fetch millions of dollars—discretion, technical pedigree, and a reputation for integrity are the primary currencies. Yet, a new entrant in the field, McLean, Virginia-based IRIS C2, is defying every convention of the industry. Operating with a bravado rarely seen in the secretive defense contracting sector, the startup has launched an aggressive campaign to acquire powerful software exploits, dangling payouts of up to $7 million.
However, the venture is not the product of seasoned intelligence veterans or Silicon Valley software architects. Behind the facade of IRIS C2 lie two of the most notorious figures in recent American political history: Jack Burkman and Jacob Wohl. Both men are convicted felons with long, documented histories of orchestrating elaborate influence operations, spreading disinformation, and running fraudulent business ventures under assumed names.
The Business Model: High-Stakes Exploits
Since its emergence in January 2025, the X (formerly Twitter) account @C2IRIS has cultivated an audience of over 4,000 followers, positioning itself as a legitimate provider of offensive cybersecurity capabilities. The firm’s public-facing pitch is simple: they are seeking the world’s most talented—often junior—engineers to build a repository of "zero-day exploits, individual primitives, partial chains, and full capabilities."
The firm claims to ignore traditional credentialing, such as college degrees or formal industry experience, favoring "raw talent" and "extremely high IQ." While their public posts on social media are filled with professional-sounding jargon about software vulnerabilities and AI, their business structure suggests a much more opaque operation.
According to government contracting records, IRIS C2 is operated by Calvexa Group LLC, a Virginia-based entity that is registered as a federal contractor but appears to hold no direct government contracts. The company’s digital footprint—specifically the redirecting of traffic between irisc2.com and calvexagroup.com—suggests a shoestring operational infrastructure that stands in stark contrast to the multimillion-dollar "bounties" they claim to offer for successful exploits.

A Chronology of Deception: The Wohl-Burkman Partnership
To understand the skepticism surrounding IRIS C2, one must look at the long, litigious, and often bizarre history of its operators. The partnership between 60-year-old Jack Burkman and 28-year-old Jacob Wohl has been defined by a repetitive cycle of creating "intelligence" firms, launching smear campaigns against political figures, and facing criminal prosecution.
The "Fake Intelligence" Era (2018–2020)
Burkman and Wohl first gained national infamy by creating bogus intelligence firms to facilitate political "stings." They were responsible for fabricating sexual assault allegations against then-FBI Director Robert Mueller and creating false narratives regarding Pete Buttigieg during the 2020 presidential cycle. Their tactics often involved press conferences filled with inconsistencies, designed to grab headlines before the claims were inevitably debunked. Similar campaigns were launched against Senator Elizabeth Warren and Vice President Kamala Harris.
The Robocall Prosecution (2020–2025)
The duo’s activities moved from the realm of political nuisance to criminal activity during the 2020 election. They orchestrated a massive robocall campaign targeting voters in battleground states, specifically aimed at suppressing the Black vote in Detroit, Michigan. The scheme resulted in multiple indictments. By 2022, both men pleaded guilty to felony telecommunications fraud in Ohio. In 2023, the Federal Communications Commission (FCC) issued a staggering $5.1 million fine against them—the largest in the history of the Telephone Consumer Protection Act. Their legal saga concluded in late 2025 with sentences of probation, though the civil liabilities remained massive, including a $1 million settlement for violating civil rights laws.
The Pivot to AI and "LobbyMatic" (2024)
Before turning their sights on cybersecurity, the pair operated a venture called "LobbyMatic," which claimed to use AI to revolutionize political lobbying. As reported by Politico, the firm was another layer of artifice. Wohl and Burkman used pseudonyms—"Jay Klein" and "Bill Sanders"—to recruit employees. When those employees discovered the true identities of their bosses, the company collapsed.
The Cybersecurity Pivot: A "Technical" Facade
Jacob Wohl’s transition into the cybersecurity market is marked by the same self-aggrandizement that characterized his early career as a hedge fund manager. In 2015, the self-styled "Wohl of Wall Street" appeared on Fox News to discuss his investment firms, only to be charged by the Arizona Corporation Commission with 14 counts of securities fraud two years later.

In a recent interview with KrebsOnSecurity, Wohl claimed that despite having no formal education or computer science training, he possesses an unparalleled technical aptitude. "I know more about tech than anyone," Wohl boasted. "My background has always been extremely technical… I’m able to create spectacularly exquisite capabilities that would make your head spin."
Wohl claims IRIS C2 employs 40 people, yet he insists they cannot list their employment on LinkedIn for "operational security reasons." This secrecy mirrors the tactics used at LobbyMatic, where employees were kept in the dark about the company’s true management until it was too late.
Implications: The Risks of "Amateur" Offensive Cyber
The entry of such individuals into the offensive cybersecurity market is sending ripples of concern through the intelligence community and private sector alike.
Security and Ethical Risks
The market for zero-day vulnerabilities—exploits that software vendors are unaware of—is traditionally governed by strict protocols. Legitimate companies like Zerodium or Crowdfence operate with deep vetting processes to ensure that exploits are sold only to vetted, democratic governments. The entry of operators like Wohl and Burkman poses several risks:
- The "Hacker" Honey Pot: If the company is not actually developing or buying legitimate exploits, it may be functioning as a data-collection mechanism. Security researchers who share their findings with IRIS C2 may be inadvertently exposing their own proprietary research to individuals with a history of exploiting information for personal or political gain.
- Regulatory Scrutiny: The U.S. government is increasingly sensitive to the export and sale of "dual-use" cyber technologies. Companies operating in this space are subject to strict ITAR (International Traffic in Arms Regulations) compliance. Given the duo’s history of fraud, the likelihood of their operation triggering federal investigations into potential illegal technology transfers or contract fraud is high.
- Reputational Damage: The cybersecurity industry relies on the "good faith" of its practitioners. By marketing offensive capabilities with the same "clickbait" style used for their previous political smear campaigns, Wohl and Burkman risk trivializing the risks associated with global cyber warfare.
The "Pardon" Connection
Further complicating the narrative is the report from journalist Molly White, detailing how Burkman and Wohl were hired as lobbyists for a Canadian cryptocurrency fraudster accused of stealing $65 million. The pair were allegedly paid a $300,000 retainer to lobby for a presidential pardon for the suspect. This connection raises questions about the true purpose of their "cybersecurity" efforts: are they building a software firm, or are they creating a new front for high-level political influence and legal maneuvering?

Conclusion
As of mid-2026, IRIS C2 remains a curiosity in the security community—a firm that manages to capture headlines through its audacious claims and the notoriety of its founders, yet lacks the institutional markers of a legitimate player. For the cybersecurity researchers and potential employees being recruited by Wohl and Burkman, the lesson of their past ventures is clear: the history of their operations is not one of innovation, but of deception.
Whether IRIS C2 is a genuine, albeit unconventional, attempt to enter the exploit market or merely the latest "shell" in a long line of fraudulent enterprises, one thing is certain: in the world of high-stakes cybersecurity, reputation is everything. And for the men behind IRIS C2, that is a currency they have long since spent.
