Cybersecurity

Cybersecurity Startup Offering Millions for Zero-Day Exploits Led by Convicted Felons Known for Conspiracy Theories and Fraudulent Ventures

A cybersecurity startup, IRIS C2, which publicly advertises multi-million dollar payouts for zero-day security vulnerabilities in widely used software, has been identified as being operated by Jack Burkman and Jacob Wohl, a notorious pair of far-right conspiracy theorists and convicted felons. Their latest foray into the tech world follows a history of creating fake intelligence companies, disseminating false claims, and running a now-defunct AI-based lobbying platform, often under assumed identities, raising significant questions about the legitimacy and ethical underpinnings of IRIS C2’s operations in a sensitive sector.

The Public Face of IRIS C2: A High-Stakes Vulnerability Buyer

IRIS C2, which launched its presence on X/Twitter (@C2IRIS) in January 2025, has rapidly garnered over 4,000 followers by frequently posting about critical security vulnerabilities, advancements in artificial intelligence, and sophisticated software exploits. The company’s digital footprint claims it is based in McLean, Virginia, and specializes in selling "offensive cybersecurity capabilities." This positioning places IRIS C2 within a highly specialized and often opaque segment of the cybersecurity market, typically populated by defense contractors, intelligence agencies, and elite security research firms.

A pinned post on the IRIS C2 X account outlines its ambitious business model: "Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience." This direct appeal for talent, emphasizing natural ability over traditional credentials, seeks to tap into a pool of gifted but potentially unseasoned researchers.

The company’s website, irisc2[.]com, reinforces this message, detailing numerous open positions and boasting an "overwhelming number of applications" on its LinkedIn page. The site explicitly states its objective: to acquire "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms." The financial incentives are substantial, with advertised payouts ranging from $10,000 to an astounding $7 million, contingent on factors such as the target system, the exploit’s reliability, and its operational value. This level of public disclosure regarding payment scales for zero-day vulnerabilities is unusually aggressive for entities typically operating in the government contracting space, which often prefer discretion due to the sensitive nature of their work.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Unmasking the Operators: Calvexa Group LLC and Its Controversial Founders

Investigations into IRIS C2’s corporate structure reveal that irisc2[.]com is operated by Calvexa Group LLC, a business registered in Virginia. According to the government contracting portal g2exchange.com, Calvexa Group LLC is listed as a federal contractor, although no direct government contracts appear to be currently active under its name. A crucial link emerges from the contact page of Calvexa Group’s website, calvexagroup[.]com, which redirects visitors to irisc2[.]com, solidifying the connection between the two entities.

Further tracing the incorporation records for Calvexa Group LLC to an address in Arlington, Virginia, leads directly to Jack Burkman, the 60-year-old founder and managing partner of the lobbying firm Burkman & Associates. When confronted with inquiries about IRIS C2, Burkman deferred all questions to his long-standing associate, 28-year-old Jacob Wohl. This referral immediately flags the operation, given the extensive and well-documented history of Burkman and Wohl, a duo infamous for a string of political hoaxes, fraudulent schemes, and legal battles.

A Chronology of Deception and Legal Entanglements

The involvement of Jack Burkman and Jacob Wohl casts a long shadow over IRIS C2, as their past ventures are characterized by widespread deception and significant legal repercussions. Their partnership has been a continuous saga of controversy, marked by attempts to manipulate public perception and engage in illicit activities.

Early Ventures and Financial Misconduct (Jacob Wohl):
Jacob Wohl’s questionable financial dealings began early in his career. By the age of 17, Wohl had already established multiple investment firms, earning him the self-proclaimed moniker "Wohl of Wall Street" after a 2015 appearance on Fox News to discuss his hedge funds. However, his financial ambitions soon collided with regulatory scrutiny. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, ultimately ordering him to pay $35,000 in restitution. This was followed by a 2019 conviction in California, where Wohl pleaded guilty to four felony counts of selling unregistered securities, resulting in a sentence of two years of probation. These early incidents established a pattern of financial impropriety and disregard for regulatory frameworks.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Political Hoaxes and Fabricated Claims (Burkman & Wohl):
The duo gained national notoriety for orchestrating a series of elaborate political hoaxes designed to discredit public figures. Their modus operandi involved creating fake intelligence companies to lend an air of legitimacy to their fabricated claims.

  • Robert Mueller and Pete Buttigieg (2018-2019): They concocted false sexual assault allegations against then-FBI Director Robert Mueller during his investigation into Russian interference in the 2016 election. Similarly, they targeted Pete Buttigieg, then mayor of South Bend, Indiana, and a rising Democratic presidential candidate, with fabricated claims.
  • Elizabeth Warren and Kamala Harris (2019): In highly publicized press conferences, Burkman and Wohl falsely alleged extramarital affairs involving Senator Elizabeth Warren (D-Mass.) and then-2020 presidential candidate Kamala Harris. These events were widely debunked and further solidified their reputation as purveyors of misinformation.
See also  Student Loan Breach Exposes 2.5M Records

The 2020 Election Robocall Scandal and Subsequent Legal Battles:
The most severe legal consequences for Burkman and Wohl stemmed from their actions during the run-up to the 2020 U.S. presidential election.

  • Voter Suppression Scheme (2020): In an egregious attempt to suppress voter turnout, particularly among Black communities, Burkman and Wohl orchestrated a robocall scheme. They made thousands of automated calls to residents in critical battleground states, spreading false information about mail-in ballots. The calls reportedly warned recipients that voting by mail could lead to their personal information being used for debt collection or even forced vaccination.
  • Ohio Indictment and Sentencing (2022-2025): The scale and intent of their actions led to federal and state investigations. In Cleveland, they were indicted on 15 felony counts for orchestrating the robocall scheme aimed at suppressing the Black vote in Detroit. After their appeals to dismiss the charges were rejected, they were sentenced to probation in late 2025.
  • Telecommunications Fraud Guilty Plea (2022): In a separate case, both Wohl and Burkman pleaded guilty to a single felony charge of telecommunications fraud in Ohio in 2022. They received sentences that included a fine, probation, and community service.
  • New York Civil Case and Settlement (March 2023): A New York civil case found Burkman and Wohl in violation of federal and state civil rights laws due to their robocall campaign. They subsequently agreed to pay a substantial $1 million settlement.
  • FCC Fine (June 2023): The Federal Communications Commission (FCC) levied a staggering $5.1 million fine against the duo for their robocall campaigns. At the time, this represented the largest fine ever sought by the FCC under the Telephone Consumer Protection Act, underscoring the severity of their violations and the broad impact of their deceptive practices.

Recent Deceptions: LobbyMatic and Crypto Pardon Attempts:
Even after their extensive legal troubles, Burkman and Wohl continued their pattern of operating under false pretenses.

  • LobbyMatic (September 2024): Politico reported that the pair were behind LobbyMatic, a now-defunct company claiming to use artificial intelligence for political lobbying. They operated LobbyMatic using pseudonyms, with Wohl adopting "Jay Klein" and Burkman going by "Bill Sanders." The deception was so profound that several LobbyMatic employees resigned upon discovering their true identities, while others only learned the truth after leaving the company. This incident highlights their ongoing willingness to mislead associates and clients alike.
  • Crypto Fraudster Retainer (March 2026 Update): In a March 2026 publication by journalist Molly White, it was revealed that Burkman and Wohl were paid a $300,000 retainer by a Canadian cryptocurrency fraudster. This individual is wanted by the United States and several other countries for allegedly stealing $65 million from crypto platforms KyberSwap and Indexed Finance. Burkman and Wohl were reportedly hired to pursue a "presidential pardon to avert a miscarriage of justice" on behalf of the accused hacker, who has not yet been convicted. This latest revelation suggests their continued involvement in highly controversial, legally precarious undertakings, even offering their "services" to individuals accused of major financial crimes.

IRIS C2: A Questionable Venture in a Sensitive Market

The offensive cybersecurity market, particularly for government contractors acquiring zero-day exploits, operates on principles of extreme discretion, high trust, and stringent ethical guidelines. Companies in this space typically employ highly credentialed experts and maintain rigorous vetting processes. IRIS C2’s approach, openly dangling millions for exploits and recruiting based on "raw talent" without formal experience, stands in stark contrast to industry norms.

During an interview, Wohl claimed that Burkman was not involved in IRIS C2’s day-to-day operations. Wohl stated that the company initially focused on penetration testing but recently pivoted to selling phone-hacking services to the government. He repeatedly referenced working on federal government contracts but declined to provide specifics, citing confidentiality. When questioned about his own qualifications, Wohl, who lacks formal education or training in computer science or information security, declared, "I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."

See also  NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support
Felons, Fraudsters Flog Offensive Cybersecurity Startup

Wohl further elaborated on IRIS C2’s process, explaining that security researchers frequently bring preliminary vulnerability findings, often an "exploit primitive" where the concept is sound but execution requires refinement. "You need that exploit to be stable and reliable, and that’s what we do," Wohl asserted. He also claimed IRIS C2 employs approximately 40 individuals, but for "operational security reasons," none are permitted to list their employment on LinkedIn. This assertion, coupled with a May post from the IRIS C2 X account stating the author’s girlfriend had no idea what he did for a living, raises serious doubts about the transparency and even the very existence of these alleged employees, especially given Burkman and Wohl’s documented history of using pseudonyms and deceiving their own staff at LobbyMatic.

Implications for the Cybersecurity Community and National Security

The brazen nature of IRIS C2’s operations, coupled with the notorious background of its founders, poses significant concerns for the cybersecurity community and potentially for national security. The market for zero-day exploits is inherently complex and ethically fraught. While legitimate actors acquire such vulnerabilities for defensive purposes or for authorized offensive capabilities (often for national defense), the involvement of individuals with a history of fraud and political manipulation introduces profound risks.

  • Risk to Researchers: Vulnerability researchers, particularly "junior engineers with raw talent," could be lured by the promise of substantial payouts without fully understanding the ethical and legal implications of working with individuals like Burkman and Wohl. They might unknowingly contribute to projects that could later be compromised or used for illicit purposes, potentially damaging their careers and reputations.
  • Credibility of the Offensive Security Market: The public association of such a sensitive market with convicted felons who have a track record of deception undermines the credibility of legitimate government contractors and offensive security firms. It blurs the lines between legitimate national security operations and potentially exploitative or fraudulent schemes.
  • National Security Concerns: If IRIS C2 were indeed to secure federal government contracts, it would raise serious questions about the vetting processes for contractors handling highly sensitive intelligence and offensive capabilities. The potential for intelligence compromise, misuse of exploits, or even direct fraud within government projects would be substantial. The lack of transparency regarding employees and operations, coupled with the founders’ history, makes any claims of "operational security" inherently suspect.
  • Ethical Erosion: The involvement of individuals who have repeatedly demonstrated a disregard for truth, law, and ethical conduct in a field that demands the highest levels of trust and integrity represents a significant ethical challenge for the cybersecurity industry.

In conclusion, the emergence of IRIS C2 as a player in the high-stakes zero-day exploit market, led by the infamous duo of Jack Burkman and Jacob Wohl, presents a stark paradox. A venture promising cutting-edge cybersecurity solutions and lucrative opportunities is, in reality, steered by individuals whose careers are defined by serial fraud, political hoaxes, and multiple felony convictions. This juxtaposition not only raises profound doubts about IRIS C2’s operational integrity and true intentions but also serves as a cautionary tale regarding the vigilance required in the increasingly complex and critical landscape of cybersecurity. The revelations demand heightened scrutiny from industry stakeholders, government agencies, and the public alike to safeguard against potential exploitation and ensure the ethical conduct of those operating within the sensitive realm of digital security.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Tech Newst
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.