A brazen new player in the high-stakes, shadow-filled world of offensive cybersecurity has emerged, promising million-dollar payouts for zero-day vulnerabilities. Yet, behind the polished veneer of the McLean, Virginia-based firm "IRIS C2" lies a far more dubious reality. The startup is the latest venture by Jacob Wohl and Jack Burkman—a duo infamous for a decade-long trail of political smears, felony convictions, fraudulent business ventures, and high-profile disinformation campaigns.
The emergence of IRIS C2, which claims to deal in the acquisition and development of sophisticated software exploits, has sent shockwaves through the cybersecurity community. While the market for zero-day vulnerabilities is inherently opaque, populated by a mix of legitimate researchers and grey-market brokers, industry veterans are expressing alarm at the brazen nature of a firm run by individuals whose careers have been defined by deception rather than technical prowess.
The Rise of IRIS C2: A High-Stakes Facade
Since its inception in January 2025, the X (formerly Twitter) account @C2IRIS has cultivated a following of over 4,000 users. The account serves as a digital storefront, frequently broadcasting requests for exploits and touting the firm’s supposed capability to monetize software vulnerabilities.
On its website, irisc2[.]com, the company presents itself as a premier destination for talent. "Our business model is this," one pinned post declares. "Attract the very best vulnerability researchers and exploit developers in the world… We don’t care if they have a college degree or industry experience."
The firm claims to acquire "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms," with payouts ranging from a modest $10,000 to an eye-watering $7 million. LinkedIn posts from the company boast of an overwhelming influx of job applications, painting a picture of a rapidly scaling enterprise. However, government contracting records tell a different story. The firm is operated under the umbrella of Calvexa Group LLC, a company registered as a federal contractor that, according to public records, has yet to secure any direct government work.
A Chronology of Deception: The Burkman-Wohl Playbook
The history of Jacob Wohl and Jack Burkman is not one of engineering innovation, but of serial fabrication. Their entry into the cybersecurity market follows a well-worn pattern of identity-shifting and institutional manipulation.

The Early Years: "Wohl of Wall Street"
Long before he attempted to position himself as a cybersecurity mogul, Jacob Wohl was a teenage financier. In 2015, he appeared on Fox News to discuss hedge funds he had founded, earning the moniker "Wohl of Wall Street." By 2017, the façade began to crack. The Arizona Corporation Commission charged Wohl’s investment funds with 14 counts of securities fraud, resulting in a $35,000 restitution order. In 2019, he pleaded guilty in California to four felony counts of selling unregistered securities, receiving two years of probation.
The Political Smear Era
Following his financial legal troubles, Wohl—in partnership with lobbyist Jack Burkman—pivoted to political disinformation. The pair became a fixture of the far-right media landscape, repeatedly launching "intelligence companies" designed to frame public figures.
Their track record includes:
- 2018: Fabricated sexual assault allegations against then-FBI Director Robert Mueller.
- 2019: Falsely alleging extramarital affairs involving Senator Elizabeth Warren and then-candidate Kamala Harris.
- 2020: Spreading false claims about then-candidate Pete Buttigieg.
The Robocall Prosecution
The duo’s most significant legal reckoning occurred in the wake of the 2020 presidential election. Wohl and Burkman orchestrated a mass-robocall campaign across multiple battleground states designed to suppress voter turnout by spreading false information about mail-in ballots.
The consequences were severe:
- 2022: They pleaded guilty to a felony count of telecommunications fraud in Ohio.
- 2023: A New York judge ruled they had violated civil rights laws, resulting in a $1 million settlement.
- 2023: The FCC imposed a record-breaking $5.1 million fine against them for their role in the robocall scheme.
- 2025: They were sentenced to probation following an indictment on 15 felony counts in Cleveland related to voter suppression in Detroit.
The AI-Lobbying Failure
Most recently, in 2024, the pair launched "LobbyMatic," an AI-driven lobbying platform. An investigation by Politico revealed that the duo operated the company using pseudonyms—Wohl as "Jay Klein" and Burkman as "Bill Sanders." The ruse collapsed when employees discovered their true identities, leading to mass resignations.

Supporting Data: The "Cybersecurity" Mirage
The transition from AI-lobbying to offensive cyber-weaponry is, for Wohl, a matter of branding. In a recent interview, Wohl dismissed his lack of formal training or education in computer science, asserting, "I know more about tech than anyone." He claimed that his knowledge is entirely self-taught and that he is capable of creating "spectacularly exquisite capabilities."
Despite these bold claims, experts remain skeptical. The market for offensive cyber-tools—which includes government agencies, defense contractors, and specialized intelligence firms—is famously secretive and relies on established vetting protocols. IRIS C2’s overt social media marketing and public solicitation of talent are antithetical to the standard practices of legitimate firms in the sector.
Furthermore, reports from journalist Molly White have added a new layer of concern. Investigations indicate that Burkman and Wohl were recently paid a $300,000 retainer by a Canadian cryptocurrency fraudster, currently wanted for a $65 million theft, to lobby for a presidential pardon. This suggests that IRIS C2 may be less a cybersecurity startup and more a shell for providing "consulting" services to individuals in legal peril.
Official Responses and Industry Skepticism
When confronted with questions regarding the nature of IRIS C2, Jacob Wohl attempted to distance his partner, Jack Burkman, from the firm’s daily operations, claiming the business began as a penetration testing venture before pivoting to "phone-hacking services." Wohl repeatedly alluded to working on federal contracts but, when pressed, cited the need for operational secrecy.
The cybersecurity community has reacted with a mix of amusement and genuine concern. While many find it difficult to believe that Wohl and Burkman possess the technical expertise required for high-level exploit development, the risk lies in the attempt. By soliciting and purchasing preliminary "primitives" from legitimate researchers, the pair could potentially aggregate enough intellectual property to become a nuisance, or worse, act as a broker for malicious actors who do not care about the origin of the code.
"The danger is not just that they are frauds," one security researcher noted. "It’s that they are using a legitimate industry as a front for their established patterns of manipulation. If they are buying exploits, who are they selling them to?"

Implications: A New Vector for Disinformation?
The implications of the IRIS C2 operation are multifaceted. First, it poses a direct risk to young, inexperienced, or financially motivated researchers who may be lured into working for a company with no ethical or legal standing. Second, it highlights a growing vulnerability in the gig-economy of cyber-intelligence: the ease with which bad actors can establish a "contractor" persona to access the global talent pool.
The history of Wohl and Burkman suggests that their ventures rarely end well for those involved. Whether it is through the loss of investment, the compromise of professional reputation, or legal entanglement, the "Wohl-Burkman" business model has consistently resulted in chaos.
As government agencies and private firms grapple with the rise of AI-driven threats, the emergence of entities like IRIS C2 serves as a grim reminder that the "cyber-arms" race is not limited to state actors and criminal syndicates. It is also being infiltrated by the same bad-faith actors who have spent years polluting the political discourse. For now, the cybersecurity industry remains on high alert, watching to see if this latest iteration of the Wohl-Burkman enterprise will implode under the weight of its own history, or if it will successfully obscure its past long enough to inflict new, digital damage.
