Executive Overview

In a dramatic crossover between political disinformation, federal criminal law, and offensive cyber operations, a Virginia-based cybersecurity startup dangling multimillion-dollar payouts for zero-day software exploits has been identified as the latest venture of convicted felons and far-right conspiracy theorists Jacob Wohl and Jack Burkman.

Operating under the brand name IRIS C2 and backed by a corporate entity named Calvexa Group LLC, the venture advertises itself as a elite defense contractor and offensive cybersecurity vendor located in McLean, Virginia. Through social media channels and an aggressive web presence, IRIS C2 claims to acquire zero-day security vulnerabilities—previously unknown software flaws with no available vendor patch—offering payouts ranging from $10,000 to $7 million for working exploit chains across major operating systems and mobile platforms.

However, an investigation into the firm’s underlying corporate infrastructure, public records, and operational history reveals that IRIS C2 is merely the latest iteration in a long series of dubious business entities masterminded by Wohl, 28, and Burkman, 60. The pair’s past ventures include fake private intelligence agencies designed to orchestrate political smears, an AI-powered lobbying firm operated under fraudulent pseudonyms, and illicit voter suppression schemes that resulted in multiple felony convictions, millions of dollars in civil penalties, and record-setting fines from federal regulators.

While the market for zero-day vulnerabilities has traditionally involved specialized defense contractors, intelligence agencies, and boutique research brokers, the brazen public recruiting strategy employed by IRIS C2 has raised significant alarm across the cybersecurity industry. Security experts, conference attendees, and federal oversight watchers warn that the venture poses substantial financial, legal, and operational risks to young or unvetted vulnerability researchers who may be lured by promises of massive payouts.

Detailed Chronology: From Financial Fraud to Offensive Cyber Operations

2015–2019: Early Financial Misconduct and Hedge Fund Schemes

The operational pattern associated with Jacob Wohl began nearly a decade ago in the financial services sector. By age 17, Wohl had dubbed himself the “Wohl of Wall Street,” appearing on national television networks to promote financial asset management services and hedge funds. This early prominence quickly unraveled under regulatory scrutiny:

Felons, Fraudsters Flog Offensive Cybersecurity Startup
  • 2017: The Arizona Corporation Commission cited Wohl and his investment funds with 14 counts of securities fraud, ultimately ordering him to pay $35,000 in restitution for misleading investors.
  • 2019: Wohl was indicted in California on multiple felony counts related to the unlawful sale of unregistered securities. He later pleaded guilty to four felony counts and was sentenced to two years of probation.

2018–2020: Fabricated Intel Agencies and High-Profile Political Smears

Partnering with veteran Washington lobbyist Jack Burkman, managing partner of Burkman & Associates, Wohl shifted his focus toward public relations stunts and political disinformation campaigns. Operating through front organizations styled as private intelligence and investigative firms—such as “Surefire Intelligence”—the duo routinely staged media events to broadcast fabricated allegations against public figures:

  • October 2018: The pair attempted to frame Special Counsel Robert Mueller during the ongoing federal investigation into Russian election interference by orchestrating false claims of sexual misconduct.
  • 2019: Wohl and Burkman held a series of press conferences leveling fabricated claims against high-profile political figures, including then-Mayor of South Bend Pete Buttigieg, Senator Elizabeth Warren, and then-presidential candidate Kamala Harris.

2020–2023: Voter Suppression, Criminal Convictions, and Regulatory Sanctions

Following the 2020 U.S. presidential election, the duo’s operations escalated from public relations hoaxes to unlawful voter suppression efforts targeted at minority populations in battleground states:

  • Late 2020: Wohl and Burkman orchestrated a widespread robocall scheme targeting tens of thousands of residents in Detroit, Cleveland, and other urban areas, disseminating deceptive claims designed to deter mail-in voting.
  • October 2022: In Cuyahoga County, Ohio, both men pleaded guilty to a felony charge of telecommunications fraud in connection with the robocall campaign. They were sentenced to community service, probation, and fines, with final probation terms extending into late 2025 following failed appeals.
  • March 2023: A federal judge in New York found Wohl and Burkman liable for violating federal and state civil rights statutes, culminating in a $1 million settlement agreement.
  • June 2023: The Federal Communications Commission (FCC) issued a historical $5.1 million fine against the duo for violating the Telephone Consumer Protection Act (TCPA)—marking the largest penalty ever assessed by the agency under the statute.

2024–2025: Pseudonymous Lobbying and the Emergence of IRIS C2

As legal judgments mounted, Wohl and Burkman adapted their operational techniques, adopting false identities to launch new commercial ventures:

  • September 2024: Media reports revealed that the pair operated a short-lived, artificial intelligence-based lobbying service called LobbyMatic. Working under the pseudonyms “Jay Klein” (Wohl) and “Bill Sanders” (Burkman), the pair claimed major corporate clients until staff members discovered their true identities and resigned.
  • January 2025: The X (formerly Twitter) account IRIS C2 (@C2IRIS) was established. Presenting itself as an offensive cybersecurity provider based in McLean, Virginia, the firm launched an aggressive public effort to procure high-tier zero-day software exploits.
  • March 2025: Investigative reporting documented that Burkman and Wohl received a $300,000 retainer from an indicted Canadian cryptocurrency actor accused of orchestrating a $65 million exploit against decentralized finance protocols (including KyberSwap and Indexed Finance). The pair was hired to lobby for a presidential pardon to evade federal prosecution.

Supporting Context & Metrics

The Zero-Day Vulnerability Market

The market for zero-day vulnerabilities sits at the intersection of state-sponsored intelligence, national defense, and private security research. Legitimate government contractors operating in the offensive cyber arena maintain strict operational security, non-disclosure protocols, and rigorous compliance programs under federal defense regulations. Private exploit brokers typically offer tiered compensation depending on the target software, execution reliability, and strategic value.

IRIS C2’s public marketing materials advertise a payout spectrum that mirrors those of established international brokers, despite lacking any verifiable track record in vulnerability research:

Felons, Fraudsters Flog Offensive Cybersecurity Startup
Target Platform / Component Advertised Capability Level Promised Payout Range (USD)
Standard Application / Web Primitive Partial Execution / Initial Flaw $10,000 – $100,000
Desktop OS / Enterprise Software Local Privilege Escalation (LPE) $100,000 – $500,000
Mobile Operating System (iOS / Android) Full Remote Code Execution (RCE) Chain $1,000,000 – $3,500,000
Zero-Click Mobile / Baseband Exploits Unauthenticated Full System Access Up to $7,000,000

Corporate Entities and Federal Records

Public filings indicate that IRIS C2 operates through Calvexa Group LLC, an entity registered in Virginia. According to government contracting databases such as G2Xchange, Calvexa Group LLC holds an active registration as a federal contractor. However, federal procurement databases show no record of active prime contracts, subcontracts, or completed delivery orders awarded to the firm by any Department of Defense or civilian intelligence agency.

Furthermore, physical corporate filings for Calvexa Group LLC point directly to a residential address in Arlington, Virginia, owned by Jack Burkman. The firm’s primary web portal (calvexagroup[.]com) automatically redirects visitors directly to the IRIS C2 commercial site (irisc2[.]com).

Official Statements and Investigative Inquiries

Jack Burkman and Jacob Wohl’s Responses

When contacted regarding the operations of IRIS C2 and Calvexa Group LLC, Jack Burkman declined to address specific operational questions, referring all media inquiries directly to Jacob Wohl.

In a direct interview, Jacob Wohl confirmed his primary leadership role in the enterprise while attempting to distance Burkman from day-to-day decisions. Key highlights from Wohl’s statements include:

  • Transition to Mobile Exploitation: Wohl stated that IRIS C2 originally operated as a standard penetration testing firm before shifting its core business model toward acquiring zero-day exploits and providing mobile phone-hacking capabilities to defense and law enforcement customers.
  • Claims of Federal Work: Wohl repeatedly asserted that the firm maintains ongoing work connected to federal government contracts. When pressed to provide specifics, contract numbers, or agency references, he stated he was “not at liberty to speak publicly about them.”
  • Lack of Formal Technical Background: Wohl admitted that he possesses no academic degrees, formal technical certifications, or prior corporate experience in computer science, software engineering, or information security, describing his knowledge as entirely self-taught.
  • Public Assertions of Expertise: Dismissing concerns regarding his lack of credentials, Wohl asserted:

    “I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin.”

Workforce and Operational Security Claims

Through its official X account, IRIS C2 actively solicits young, non-credentialed talent, explicitly noting that it targets “junior engineers with raw talent/extremely high IQ” regardless of academic or professional backgrounds. Wohl claimed during interviews that IRIS C2 employs approximately 40 personnel.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

However, Wohl acknowledged that none of these employees are permitted to list IRIS C2 or Calvexa Group as their employer on professional networking platforms like LinkedIn, citing strict “operational security” (OPSEC) requirements. Independent verification of any technical staff associated with the company remains impossible, echoing the pseudonymous structure previously used by Wohl and Burkman during their operations at LobbyMatic.

Future Outlook and Industry Risks

Implications for the Cybersecurity Research Community

The entry of convicted felons with a documented history of fraud into the zero-day exploit market introduces significant risks for independent security researchers:

  • Financial and Intellectual Property Risk: Independent vulnerability researchers who submit novel exploit primitives to unvetted entities risk having their intellectual property stolen or resold without receiving the advertised financial compensation.
  • Legal Exposure: Disclosing highly sensitive zero-day exploits to unauthorized brokers or pseudonymous entities can expose researchers to criminal liability under laws governing export control, national security, and intellectual property protection.
  • Reputational Damage: Security professionals who engage with entities linked to public disinformation agents risk severe professional fallout and potential blacklisting by legitimate security firms and bug bounty programs.

Regulatory and Law Enforcement Scrutiny

Given the legal history of both operators, IRIS C2 and Calvexa Group LLC are likely to face heightened scrutiny from state and federal regulators. Observers point out that because offensive cyber tools and zero-day vulnerabilities fall under stringent export compliance frameworks—including International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR)—any attempt by the firm to acquire or export sophisticated exploits could trigger federal law enforcement intervention.

Furthermore, as Wohl and Burkman remain under strict post-conviction supervisory conditions from their state felony cases, any fraudulent commercial activities undertaken through IRIS C2 could lead to immediate probation revocations and further judicial proceedings.

Leave a Reply

Your email address will not be published. Required fields are marked *