Convicted Felons and Conspiracy Theorists Launch Offensive Cybersecurity Startup IRIS C2 to Acquire Multi-Million Dollar Zero-Day Exploits

The intersection of high-stakes offensive cybersecurity and political disinformation has reached a new and controversial milestone with the emergence of IRIS C2, a startup claiming to offer millions of dollars for the acquisition of zero-day vulnerabilities. While the market for software exploits—flaws unknown to the software’s creators—is typically a discreet world of elite researchers and government contractors, IRIS C2 has taken an unusually brazen approach to recruitment and publicity. Investigations into the company’s origins reveal that it is the latest venture of Jack Burkman and Jacob Wohl, a pair of notorious conspiracy theorists and convicted felons with a documented history of financial fraud, disinformation campaigns, and elaborate corporate deceptions.
Operating under the corporate umbrella of Calvexa Group LLC, IRIS C2 has established a significant presence on social media, particularly on X (formerly Twitter), where its account @C2IRIS has amassed thousands of followers since early 2025. The company positions itself as a premier destination for "vulnerability researchers and exploit developers," specifically targeting "junior engineers with raw talent" and high cognitive abilities, regardless of their formal education or industry experience. This unconventional recruiting pitch is paired with the promise of massive financial rewards, with the company’s website claiming payouts ranging from $10,000 to as high as $7 million for full-chain exploits across major software platforms.
The Business Model and Operations of IRIS C2
The stated mission of IRIS C2 is the acquisition and refinement of "zero-day exploits, individual primitives, partial chains, and full capabilities." In the cybersecurity industry, a "zero-day" represents a vulnerability for which no patch exists. A "chain" refers to a sequence of multiple exploits used together to bypass various layers of security. Such capabilities are highly sought after by intelligence agencies and law enforcement for surveillance and offensive cyber operations.
According to the company’s public-facing materials, IRIS C2 is headquartered in McLean, Virginia, a hub for the United States defense and intelligence community. However, corporate registration data paints a different picture. Records for Calvexa Group LLC, the entity operating the IRIS C2 website, list an address in Arlington, Virginia, which serves as the residence and office of Jack Burkman, the 60-year-old founder of the lobbying firm Burkman & Associates.

In interviews and public statements, Jacob Wohl, Burkman’s 28-year-old associate, has claimed that IRIS C2 currently employs approximately 40 individuals. However, Wohl maintains that none of these employees are permitted to list their affiliation with the company on professional networks like LinkedIn, citing "operational security" (OPSEC). This lack of transparency is a hallmark of Wohl and Burkman’s previous ventures, which often relied on pseudonyms and shell companies to mask the founders’ identities and legal histories.
A Legacy of Disinformation and Legal Malfeasance
The involvement of Wohl and Burkman in a field as sensitive as offensive cybersecurity has raised significant alarms within the security community. The duo is best known not for technological innovation, but for a series of failed and often illegal attempts to influence American politics through fabrication.
Between 2018 and 2020, Wohl and Burkman orchestrated several high-profile smear campaigns against public figures. These included the creation of a fake private intelligence firm, "Burkman & Associates," which they used to hold press conferences alleging sexual misconduct by then-FBI Director Robert Mueller, Senator Elizabeth Warren, and then-presidential candidate Kamala Harris. In each instance, the allegations were quickly debunked as fabrications involving paid actors or coerced witnesses.
The legal consequences for their activities have been severe and multifaceted:
- Voter Suppression and Robocalls: In the wake of the 2020 U.S. Presidential Election, Wohl and Burkman were indicted for orchestrating a massive robocall campaign targeting minority voters in battleground states. The calls disseminated false information about mail-in ballots to discourage voting. In 2022, they pleaded guilty to felony telecommunications fraud in Ohio and were later sentenced to probation and community service.
- FCC Penalties: In June 2023, the Federal Communications Commission (FCC) issued a $5.1 million fine against the pair—the largest fine in the agency’s history for violations of the Telephone Consumer Protection Act—related to their illegal robocall operations.
- Securities Fraud: Jacob Wohl’s history of financial impropriety dates back to his teenage years. Dubbed the "Wohl of Wall Street," he was charged with 14 counts of securities fraud in Arizona in 2017. In 2019, he pleaded guilty in California to felony counts related to the sale of unregistered securities.
- Civil Rights Violations: A New York judge ruled in 2023 that Wohl and Burkman had violated both federal and state civil rights laws through their voter intimidation tactics, resulting in a $1 million settlement agreement.
The LobbyMatic Precedent: Deception in the AI Sector
IRIS C2 is not the first time Wohl and Burkman have attempted to pivot into emerging technology. In 2024, reports surfaced regarding a now-defunct venture called LobbyMatic, which claimed to use artificial intelligence to revolutionize the lobbying industry. Investigation by journalists at Politico revealed that Wohl and Burkman were running the company using the pseudonyms "Jay Klein" and "Bill Sanders," respectively.

The use of aliases allowed the duo to hire legitimate staff and court corporate clients who were unaware of the founders’ criminal records and reputations. When the true identities of "Klein" and "Sanders" were revealed, several employees resigned immediately, citing the ethical breach and the potential for reputational damage. This pattern of using "front" identities suggests that the current claims of 40 anonymous employees at IRIS C2 may be a similar fabrication or a method of insulating the workforce from the founders’ legal baggage.
The Global Market for Zero-Day Exploits
To understand the potential impact of IRIS C2, one must look at the broader "gray market" for cyber exploits. Legitimate companies like Zerodium and Crowdfense act as brokers, purchasing vulnerabilities from independent researchers and selling them to vetted government clients. The prices offered by IRIS C2—up to $7 million—are competitive with the highest tiers of the global market, where a zero-click exploit for iOS or Android can command such sums.
However, the legitimacy of a zero-day broker depends entirely on its vetting processes and its client base. Established brokers operate with a level of discretion and legal oversight that contrasts sharply with IRIS C2’s public "bounty" posts on social media. Experts suggest that a company run by individuals with multiple felony convictions for fraud and disinformation is unlikely to pass the rigorous background checks required for direct federal contracting, despite Calvexa Group’s registration in the federal contractor portal.
Furthermore, there are concerns that IRIS C2 may be a "honeypot" or a data-harvesting operation. By attracting young, talented researchers with the promise of large payouts, the company could potentially acquire sensitive research without the intent or ability to pay, or worse, use the research for unauthorized or malicious purposes.
Connections to International Cybercrime
Adding another layer of complexity to the founders’ activities is a recent report indicating their involvement with international cybercrime figures. In early 2024, it was revealed that Wohl and Burkman were paid a $300,000 retainer by a Canadian individual accused of orchestrating massive cryptocurrency thefts from platforms such as KyberSwap and Indexed Finance.

The retainer was purportedly intended to secure a "presidential pardon" for the accused hacker, who is currently facing charges related to a $65 million exploit. This connection highlights a burgeoning relationship between the duo and the world of high-value cybercrime, suggesting that IRIS C2 may be an attempt to formalize their role as intermediaries between hackers and those seeking to exploit or litigate cyber vulnerabilities.
Implications for the Cybersecurity Community
The emergence of IRIS C2 represents a unique challenge for the cybersecurity industry and law enforcement. If the company is indeed acquiring functional zero-day exploits, it places powerful offensive tools in the hands of individuals with a proven track record of using technology to subvert democratic processes and engage in fraud.
Industry analysts warn that the "gamification" of exploit sales on social media could entice inexperienced researchers into legal or ethical traps. "The offensive security market relies on a foundation of trust and professional ethics," says one cybersecurity consultant. "When you introduce actors who have been legally sanctioned for systemic lying, the entire ecosystem is put at risk."
As of mid-2025, IRIS C2 continues to post recruitment advertisements and technical commentary on social media. While Jacob Wohl claims he is building "spectacularly exquisite capabilities," the cybersecurity community remains skeptical, viewing the venture as a potential continuation of the founders’ long history of elaborate "grifts." Whether IRIS C2 will become a functional player in the exploit market or collapse under the weight of its founders’ reputations remains to be seen, but its existence serves as a stark reminder of the evolving threats at the intersection of technology, crime, and disinformation.







