Cybersecurity and Privacy

Convicted Felons and Conspiracy Theorists Jack Burkman and Jacob Wohl Reemerge with IRIS C2, a High-Stakes Zero-Day Cybersecurity Startup

The cybersecurity landscape has long been a frontier for high-stakes technological development, national security interests, and a complex marketplace for digital weaponry. However, the emergence of a new entity, IRIS C2, has raised significant alarms within the intelligence and information security communities. This startup, which claims to offer millions of dollars for "zero-day" security vulnerabilities, is not led by seasoned computer scientists or defense contractors, but by a pair of notorious far-right conspiracy theorists and convicted felons: Jack Burkman and Jacob Wohl. Their transition from political smear campaigns and fraudulent financial schemes to the offensive cybersecurity market represents a startling shift that has observers questioning the legitimacy and safety of their latest venture.

Operating out of McLean, Virginia—a hub for the American defense and intelligence industry—IRIS C2 began its public outreach through social media in early 2025. Its presence on X (formerly Twitter) under the handle @C2IRIS has rapidly accumulated a following of over 4,000 users. The account frequently disseminates content regarding software exploits, artificial intelligence, and the intricacies of offensive cyber operations. The company’s stated business model is as bold as it is unconventional: it seeks to bypass traditional academic and professional gatekeeping to recruit "junior engineers with raw talent" and "extremely high IQ," explicitly stating that they do not require college degrees or industry experience.

The Business of Zero-Day Exploits

At the core of IRIS C2’s public-facing operation is the acquisition of zero-day vulnerabilities—software flaws that are unknown to the vendor and for which no patch exists. These vulnerabilities are the "crown jewels" of the hacking world, providing a window of opportunity for state actors, intelligence agencies, or cybercriminals to infiltrate systems undetected. IRIS C2’s website, irisc2.com, lists a tiered payout structure for these exploits, ranging from $10,000 for minor flaws to as much as $7 million for full, reliable exploit chains on major platforms.

This price range is comparable to the legitimate "grey market" for exploits, where brokers like Zerodium and Crowdfense sell capabilities to government agencies. However, the transparency and history of the individuals behind IRIS C2 stand in stark contrast to the circumspect nature of established defense contractors. The company claims to be looking for "individual primitives, partial chains, and full capabilities across all major platforms," suggesting an ambition to provide comprehensive hacking tools for mobile devices, desktop operating systems, and critical infrastructure.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Investigations into the corporate structure of IRIS C2 reveal a complex web of shell companies and registrations. According to the government contracting portal G2Exchange, the website is operated by Calvexa Group LLC. While Calvexa Group is registered as a federal contractor, there is currently no public record of the firm being awarded any direct government contracts. The physical address for Calvexa Group in Arlington, Virginia, is the known residence and office of Jack Burkman, the 60-year-old founder of the lobbying firm Burkman & Associates.

A Legacy of Deception and Legal Turmoil

To understand the concerns surrounding IRIS C2, one must look at the extensive and documented history of its principals. Jacob Wohl, 28, and Jack Burkman have spent the better part of the last decade embroiled in legal battles and public scandals. Their partnership has been defined by the creation of "fake intelligence" companies used to facilitate political disinformation campaigns.

In 2018 and 2019, the duo held a series of amateurish press conferences intended to frame prominent public figures. They famously attempted to smear then-FBI Director Robert Mueller with fabricated sexual assault allegations during the height of the Special Counsel investigation into Russian interference. They later targeted Pete Buttigieg, Senator Elizabeth Warren, and then-Senator Kamala Harris with similarly baseless claims of misconduct and extramarital affairs. These operations often involved the use of paid actors and fraudulent documentation, leading to widespread condemnation and a series of civil and criminal consequences.

The legal repercussions for their activities escalated following the 2020 presidential election. Wohl and Burkman were indicted in several states for orchestrating a massive robocall campaign aimed at suppressing voter turnout in minority communities. The calls disseminated false information claiming that mail-in ballots would be used by law enforcement to track old warrants and by the CDC to track mandatory vaccinations.

In late 2025, after a long appeals process, the pair was sentenced to probation in Ohio after pleading guilty to telecommunications fraud. This followed a landmark 2023 ruling in New York where a judge found they had violated federal and state civil rights laws, resulting in a $1 million settlement. Furthermore, the Federal Communications Commission (FCC) levied a record-breaking $5.1 million fine against them—the largest fine ever sought under the Telephone Consumer Protection Act.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

From LobbyMatic to Offensive Cyber

Before the launch of IRIS C2, Wohl and Burkman attempted to pivot into the world of artificial intelligence with a company called LobbyMatic. Marketed as an AI-driven platform to revolutionize political lobbying, the company reportedly secured several high-profile clients. However, an investigation by Politico in late 2024 revealed that the duo was running the company under assumed names. Wohl adopted the pseudonym "Jay Klein," while Burkman went by "Bill Sanders."

The deception led to a mass exodus of staff. Employees discovered their bosses’ true identities only after joining the firm, with some resigning immediately upon learning they were working for two of the most infamous political tricksters in the United States. This pattern of using pseudonyms and "operational security" to hide the founders’ identities appears to have carried over to IRIS C2. Wohl has admitted that none of the company’s claimed 40 employees are permitted to list IRIS C2 on their LinkedIn profiles, a move he justifies as a necessity for "OPSEC" (operational security).

In a recent interview, Wohl boasted about his technical prowess, despite having no formal education in computer science. "I know more about tech than anyone," Wohl claimed, describing his capabilities as "spectacularly exquisite." He characterized IRIS C2’s role as a refiner of exploits, taking "primitives" found by independent researchers and turning them into stable, reliable tools for government use.

The Risks of Unregulated Exploit Brokerage

The entry of individuals with a history of fraud into the zero-day market presents unique risks to the cybersecurity ecosystem. The trade of exploits is a sensitive business that relies on a high degree of trust and discretion. Researchers who sell their findings to brokers expect that the vulnerabilities will be handled responsibly—usually sold to democratic governments for law enforcement or national security purposes.

Analysts worry that IRIS C2 may serve as a "honeypot" for young, unsuspecting researchers. By dangling million-dollar payouts, Wohl and Burkman could potentially acquire highly sensitive technical data from researchers who fail to perform due diligence on the company’s leadership. There is also the risk that the capabilities acquired by such an entity could be sold to the highest bidder, including adversarial nation-states or organized crime syndicates, regardless of the founders’ claims of working with the U.S. government.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Furthermore, the duo’s recent involvement with international fugitives adds another layer of suspicion. Reports indicate that Burkman and Wohl were recently paid a $300,000 retainer by a Canadian cryptocurrency hacker wanted by the U.S. for allegedly stealing $65 million. The pair was reportedly hired to lobby for a presidential pardon, demonstrating that their services remain available to those seeking to circumvent the legal system through unconventional means.

Chronology of Key Events

  • 2015: Jacob Wohl gains media attention as the "Wohl of Wall Street" before being charged with securities fraud in Arizona.
  • 2018-2019: Wohl and Burkman launch a series of "intelligence" firms to smear Robert Mueller, Pete Buttigieg, and Kamala Harris.
  • 2020: The duo orchestrates a robocall campaign to suppress votes in the U.S. Presidential Election.
  • 2022-2023: Legal hammer falls; the pair faces felony charges in Ohio, a $1 million civil settlement in New York, and a $5.1 million FCC fine.
  • 2024: The "LobbyMatic" scandal breaks, revealing the pair operated an AI lobbying firm under the pseudonyms Jay Klein and Bill Sanders.
  • January 2025: The IRIS C2 social media presence is established, marking their entry into the offensive cybersecurity market.
  • June 2025: IRIS C2 begins active recruitment of "high IQ" researchers, offering up to $7 million for software exploits.

Industry Implications and National Security Concerns

The broader implications of IRIS C2’s existence touch upon the lack of regulation in the private exploit market. While the U.S. government has various mechanisms for vetting contractors, the "grey market" for zero-days operates in a legal twilight zone. If IRIS C2 is indeed successful in acquiring high-level exploits, the lack of oversight regarding where those exploits end up is a significant national security concern.

Veteran cybersecurity researchers have expressed skepticism regarding the company’s claims. The technical difficulty of developing a "stable and reliable" exploit from a "primitive" is immense, requiring a level of expertise that neither Wohl nor Burkman has ever demonstrated. Some suggest that IRIS C2 may be less of a functional cybersecurity firm and more of a "data harvesting" operation, designed to collect valuable research under false pretenses.

As IRIS C2 continues to post about its "exquisite capabilities" and high-value payouts, the cybersecurity community remains on high alert. The intersection of high-end cyber weaponry and individuals with a documented history of fabrication, fraud, and political subversion creates a volatile mix. Whether IRIS C2 is a legitimate attempt at a business pivot or merely the latest in a long line of "spectacularly exquisite" scams remains to be seen, but the history of its founders suggests that caution is the only prudent response for any researcher or government agency considering an engagement with the firm.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Device Kick
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.