The “Wohl of Wall Street” Returns: Inside the Shadowy Cybersecurity Startup Linked to Infamous Con Artists

A new player has emerged in the high-stakes, opaque world of zero-day vulnerability trading, promising payouts of up to $7 million for the world’s most sophisticated software exploits. But behind the polished facade of IRIS C2—a McLean, Virginia-based firm claiming to provide “offensive cybersecurity capabilities”—lies a duo with a long, documented history of political disinformation, federal indictments, and fraudulent business ventures.

The company, which operates through the X (formerly Twitter) account @C2IRIS, is the latest iteration of the professional partnership between 28-year-old Jacob Wohl and 60-year-old Jack Burkman. The pair, whose previous exploits include creating fake intelligence firms to smear public figures and orchestrating illegal mass-robocall campaigns, now appear to be pivoting toward the lucrative and highly sensitive market for government-grade cyber weaponry.

Main Facts: A Billion-Dollar Facade

IRIS C2 presents itself as a cutting-edge boutique firm specializing in the acquisition of “zero-day exploits, individual primitives, partial chains, and full capabilities.” Since its inception in January 2025, the company has leveraged social media to aggressively recruit talent, specifically targeting junior engineers with “extremely high IQ” and raw technical ability, explicitly stating that traditional academic credentials are irrelevant to their hiring process.

The company is legally tethered to Calvexa Group LLC, a Virginia-based entity registered as a federal contractor. While government contracting portals show that Calvexa Group is technically cleared to conduct business with federal agencies, records indicate the firm currently holds no direct, active government contracts.

Despite the lack of public-sector work, the company’s website and leadership maintain that they are deeply involved in the offensive cyber ecosystem. The operational model relies on the recruitment of researchers who can provide the "missing links" in software exploits, which IRIS C2 then promises to refine into stable, reliable tools for potential government clients.

The Architects of Disinformation: A Chronology

To understand the skepticism surrounding IRIS C2, one must examine the track record of its principals. The careers of Jack Burkman and Jacob Wohl are defined by a pattern of escalating legal trouble and elaborate, often bizarre, deception.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

2015–2019: The "Wohl of Wall Street" Era

Jacob Wohl first gained notoriety as a teenager, branding himself as a financial prodigy and hedge fund manager. His tenure on cable news as a market expert came to an abrupt halt in 2017 when the Arizona Corporation Commission charged him and his funds with 14 counts of securities fraud, resulting in a $35,000 restitution order. By 2019, Wohl had pleaded guilty in California to four felony counts related to the sale of unregistered securities, earning two years of probation.

2018–2020: The Smear Campaigns

During the height of the Trump-era political climate, Wohl and Burkman pivoted from finance to political “intelligence.” They were frequently linked to fake companies designed to circulate manufactured scandals. Their targets included high-profile political figures, such as then-FBI Director Robert Mueller, Senator Elizabeth Warren, then-candidate Kamala Harris, and then-Mayor Pete Buttigieg. In each instance, the pair held press conferences featuring witnesses who were later revealed to be actors or individuals coerced into making fabricated claims of sexual misconduct or illicit affairs.

2020–2025: Legal Reckoning and Robocalls

The most significant legal blow to the pair arrived in the wake of the 2020 presidential election. Wohl and Burkman were indicted in Ohio on 15 felony counts for orchestrating a mass-robocall campaign designed to suppress the Black vote in Detroit by spreading misinformation regarding mail-in ballots.

The legal consequences were severe:

  • 2022: The duo pleaded guilty to telecommunications fraud in Ohio, resulting in fines, community service, and probation.
  • 2023: A New York civil court ruled that their activities violated civil rights laws, forcing a $1 million settlement.
  • 2023: The Federal Communications Commission (FCC) levied a $5.1 million fine against them—the largest in the history of the Telephone Consumer Protection Act—for their persistent, illegal robocalling.
  • Late 2025: Following failed appeals, the pair received final sentencing on their felony counts, narrowly avoiding significant prison time but remaining under strict judicial supervision.

Supporting Data: From LobbyMatic to IRIS C2

The pattern of rebranding is central to the Burkman-Wohl operational strategy. In 2024, Politico exposed the existence of "LobbyMatic," an AI-driven lobbying platform. The company claimed to represent major corporate clients, but investigators found the firm was a ghost operation. Wohl operated under the pseudonym “Jay Klein,” while Burkman used the name “Bill Sanders.” Employees were kept in the dark about the identities of their employers, with some resigning immediately upon discovering the truth.

IRIS C2 appears to be a direct continuation of this behavior. While Wohl claims the company employs roughly 40 people, none are permitted to list their employment on professional networks like LinkedIn, citing "operational security." This lack of transparency, coupled with Wohl’s penchant for pseudonyms, suggests that the “40 employees” may either be unaware of their employer’s true background or may not exist in the capacity Wohl describes.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Furthermore, investigative journalist Molly White reported in March 2026 that the pair accepted a $300,000 retainer from an accused cryptocurrency hacker. The duo was allegedly hired to lobby for a presidential pardon on behalf of the individual, who is wanted by international authorities for the theft of $65 million from DeFi platforms.

Official Responses and Interviews

When contacted by KrebsOnSecurity, Wohl attempted to distance himself from the duo’s past, claiming that Burkman is not involved in the day-to-day operations of IRIS C2. However, the business is physically based at an address occupied by Burkman’s firm, and Burkman himself directed inquiries to Wohl when approached for comment.

Wohl, who lacks any formal computer science education or professional cybersecurity certification, was defiant when questioned about his qualifications. “I know more about tech than anyone,” Wohl stated in an interview. “People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin.”

Wohl admitted that the company’s initial focus on penetration testing had shifted toward phone-hacking services. When pressed on which federal government agencies he was supposedly contracting with, Wohl cited national security concerns, refusing to provide specific documentation or agency names.

Implications for the Cybersecurity Industry

The emergence of IRIS C2 serves as a grim reminder of the "wild west" nature of the zero-day exploit market. While legitimate firms in this space—such as Zerodium or Crowdfense—operate with high levels of discretion and rigorous vetting, the entry of actors like Wohl and Burkman introduces significant volatility and ethical concerns.

1. The Risk of Malicious Actor Involvement

The market for zero-day vulnerabilities is inherently dangerous. If a company with a documented history of fraud and criminal conspiracy is handling sensitive exploit data, the potential for that data to be leaked, sold to foreign adversaries, or used for private extortion is astronomically high.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

2. Talent Exploitation

By targeting junior developers and “clout-chasers” with promises of million-dollar payouts, IRIS C2 is preying on the most vulnerable segment of the cybersecurity workforce. Young researchers, enticed by the prospect of high pay and the “glamour” of offensive research, may find themselves unknowingly complicit in illegal activities or, at the very least, associated with a firm that will almost certainly collapse under future legal scrutiny.

3. The Erosion of Trust in Government Contracting

The fact that a company run by convicted felons can maintain a footprint in the federal contracting space raises questions about the efficacy of current vetting processes. While Calvexa Group LLC currently holds no direct contracts, the mere perception of their involvement in government work could damage the reputation of legitimate security contractors who operate with transparency and ethics.

4. Future Outlook

As of mid-2026, IRIS C2 continues to post content on social media, actively soliciting vulnerabilities. Whether the company is a genuine, albeit ethically questionable, enterprise or yet another elaborate grift remains to be seen. However, given the historical trajectory of Wohl and Burkman’s ventures, history suggests that the firm is likely to implode long before it delivers any “exquisite capabilities” to the federal government. For now, the cybersecurity community remains on high alert, viewing the firm not as a legitimate vendor, but as a dangerous anomaly in an already high-risk industry.

By Nana