From Lobbying Schemes to Zero-Day Exploits: The Shadowy Rebirth of Wohl and Burkman

A new player has emerged in the high-stakes, opaque market for zero-day security vulnerabilities—a firm promising payouts of up to $7 million for the discovery of software exploits. Known as IRIS C2, the company claims to be based in McLean, Virginia, and has rapidly cultivated an online presence on X (formerly Twitter). However, beneath the surface of this purportedly cutting-edge cybersecurity startup lies a familiar and controversial duo: far-right conspiracy theorists and convicted felons Jacob Wohl and Jack Burkman.

The venture, which operates under the corporate umbrella of Calvexa Group LLC, represents the latest pivot for two men whose careers have been defined by a pattern of alleged fraud, elaborate disinformation campaigns, and the deployment of fake personas. While IRIS C2 presents itself as a sophisticated entity capable of delivering "offensive cybersecurity capabilities" to government clients, its pedigree suggests a far more precarious reality.

The IRIS C2 Business Model: A Digital Siren Song

Since its inception in January 2025, the IRIS C2 account (@C2IRIS) has grown to over 4,000 followers, acting as a recruitment funnel for software exploit developers. The company’s public messaging is explicitly meritocratic, stating that it seeks "junior engineers with raw talent/extremely high IQ," while pointedly dismissing the necessity of college degrees or traditional industry experience.

The firm’s website, irisc2[.]com, outlines an aggressive acquisition strategy for "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms." The financial incentives are significant, with payouts ranging from $10,000 to $7 million. This "bounty" model is common in the gray-market world of vulnerability research, yet the brazen, public nature of the solicitation is highly atypical. Most firms operating in the vulnerability acquisition space maintain extreme discretion to protect their government or corporate clients. IRIS C2, by contrast, behaves more like a tech-startup disruptor, actively soliciting applications via LinkedIn and professional conferences.

A History of Deception: The Wohl-Burkman Chronology

To understand the skepticism surrounding IRIS C2, one must examine the documented history of its operators. Jacob Wohl, 28, and Jack Burkman, 60, have spent the better part of the last decade embroiled in legal battles and public controversies.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

The Rise of "Wohl of Wall Street" (2015–2017)

Wohl first gained notoriety as a teenager, branding himself "Wohl of Wall Street" while appearing on cable news to discuss hedge funds he had founded. This early success was short-lived. In 2017, the Arizona Corporation Commission charged Wohl and his firms with 14 counts of securities fraud, resulting in a $35,000 restitution order. By 2019, he had pleaded guilty in California to four felony counts related to the sale of unregistered securities, earning him two years of probation.

The Disinformation Era (2018–2020)

Between 2018 and 2020, Wohl and Burkman pivoted to political sabotage. They became known for creating "intelligence" companies used to disseminate fabricated claims against public figures. Their targets included then-FBI Director Robert Mueller, Mayor Pete Buttigieg, Senator Elizabeth Warren, and Kamala Harris. These efforts often involved press conferences filled with unsubstantiated allegations of sexual misconduct or infidelity, which were quickly debunked.

The Robocall Prosecution (2020–2025)

Perhaps the most damaging episode occurred following the 2020 presidential election, when the pair orchestrated a mass robocall campaign targeting voters in battleground states with disinformation about mail-in ballots. The fallout was severe:

  • 2022: Both pleaded guilty to a single felony count of telecommunications fraud in Ohio.
  • 2023: A New York court found they had violated civil rights laws, resulting in a $1 million settlement.
  • 2023: The Federal Communications Commission (FCC) levied a $5.1 million fine against them—the largest in the history of the Telephone Consumer Protection Act.
  • 2025: They were sentenced to probation after a lengthy legal battle regarding 15 felony counts in Cleveland related to voter suppression in Detroit.

The AI-Lobbying Pivot (2024)

Before turning their attention to cybersecurity, the duo operated a firm called "LobbyMatic," which claimed to use artificial intelligence to revolutionize political lobbying. As reported by Politico, the venture was a front for the pair to operate under aliases—Wohl as "Jay Klein" and Burkman as "Bill Sanders." The facade crumbled when employees realized their true identities, leading to a series of resignations.

Supporting Data: The Infrastructure of IRIS C2

Evidence linking IRIS C2 to the duo is both digital and physical. Incorporation records for Calvexa Group LLC, the entity operating irisc2[.]com, point to an Arlington, Virginia address that is the registered office of Burkman & Associates. When questioned about the firm, Burkman directed inquiries to Wohl.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Furthermore, the firm’s operational security is paradoxically porous. While Wohl claims that his roughly 40 employees are forbidden from listing their work on LinkedIn—citing "operational security"—the company maintains an active, public-facing LinkedIn page and an X account that openly discusses its business.

Industry experts note that the "zero-day" market is typically populated by a quiet, vetted group of researchers. The emergence of a company that simultaneously claims to be a high-level government contractor while lacking the traditional security clearances or corporate history expected of such entities has raised alarms. G2Exchange, a federal contracting portal, confirms that while Calvexa Group is a registered contractor, it currently holds no direct federal contracts, casting doubt on the firm’s claims of providing capabilities to the government.

Official Responses and Defensive Posture

In a recent interview with KrebsOnSecurity, Jacob Wohl addressed the scrutiny surrounding his new venture. He acknowledged that IRIS C2 originally began as a penetration testing company but has since pivoted to selling "phone-hacking services." When pressed for evidence of these government contracts, Wohl declined to provide details, citing the sensitive nature of the work.

Wohl also dismissed concerns regarding his lack of formal education in computer science or cybersecurity, asserting, "I know more about tech than anyone." He claimed that his background has always been "extremely technical" and that his role involves taking raw, "preliminary" exploit findings from researchers and refining them into "stable and reliable" capabilities.

When asked about the company’s internal operations, Wohl maintained that he is the primary driver of the business and that Burkman is not involved in day-to-day operations—a statement that stands in contrast to the shared address and his own redirection of inquiries.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Implications: The Risks of "Fringe" Cybersecurity

The implications of IRIS C2’s existence are twofold. First, there is the risk of potential exploitation of the researchers themselves. If the company is indeed collecting raw vulnerability data without the capacity or intent to handle it responsibly, it risks exposing researchers to legal jeopardy or intellectual property theft.

Second, the involvement of individuals with histories of criminal fraud in the sensitive arena of offensive cyber capabilities is a national security concern. The market for zero-days is a core component of modern cyber warfare and espionage. If a company led by convicted fraudsters can gain even a foothold in the supply chain for government agencies, it poses significant risks of incompetence, misrepresentation, or outright malicious exploitation.

As noted by recent reports—including a March 2026 investigation by journalist Molly White—the pair was recently linked to a $300,000 retainer paid by a Canadian cryptocurrency fraudster seeking a presidential pardon for a $65 million hacking scheme. This suggests that the duo’s interest in the cybersecurity sector may be less about technical innovation and more about finding new avenues to leverage their connections for high-stakes, ethically compromised deals.

For the cybersecurity community, the emergence of IRIS C2 serves as a cautionary tale. While the allure of million-dollar payouts is strong, the provenance of the entity offering the money is often the most important security indicator of all. In the case of Wohl and Burkman, the track record suggests that behind the "spectacularly exquisite" claims of technical prowess lies a history that is, at best, a fiction.