Executive Overview: Convicted Felons Pivot to Offensive Cyber Capabilities
A shadowy cybersecurity startup offering millions of dollars to purchase zero-day software vulnerabilities has been uncovered as the latest venture of Jack Burkman and Jacob Wohl—a pair of far-right conspiracy theorists, disgraced political operatives, and convicted felons. Operating under the name IRIS C2 and backed by a corporate shell called Calvexa Group LLC, the entity claims to acquire high-grade offensive cyber capabilities and sell specialized phone-hacking services to the United States federal government.
The discovery of IRIS C2 reveals a alarming transition by two of America’s most high-profile political fraudsters into the opaque, high-stakes market for zero-day software exploits. Over the past decade, Wohl and Burkman have established a distinct operational pattern: launching fraudulent intelligence firms, running smear campaigns with fabricated sexual assault allegations against public figures, executing unlawful voter suppression schemes, and managing now-defunct corporate entities under fictitious identities.
Promising exploit payouts ranging from $10,000 to $7 million, IRIS C2 aggressively targets young, uncredentialed vulnerability researchers. However, behind the startup’s claims of million-dollar bounties and undisclosed federal contracts lies a familiar apparatus of corporate obfuscation, pseudonymous operations, and questionable claims. Cybersecurity experts and vulnerability researchers are being warned to exercise extreme caution when dealing with the entity.
Detailed Chronology: A History of Fabrications, Fraud, and Disinformation
To understand the operational model behind IRIS C2, it is necessary to examine the decade-long sequence of financial securities violations, political fabrications, and legal sanctions that define the careers of Jacob Wohl and Jack Burkman.
+-----------------------------------------------------------------------------------+
| CHRONOLOGY OF OPERATIONS |
+------+----------------------------------------------------------------------------+
| 2015 | Wohl launches hedge funds as "Wohl of Wall Street"; later cited for fraud. |
| 2017 | Arizona regulators order Wohl to pay $35,000 in securities fraud case. |
| 2018 | Surefire Intelligence created; false allegations levied against Mueller. |
| 2019 | Wohl pleads guilty in CA to 4 felony counts of selling unregistered stock. |
| 2020 | Pair orchestrates voter suppression robocalls targeting Black voters. |
| 2022 | Guilt pleas entered in Ohio for telecommunications fraud; probation issued. |
| 2023 | FCC levies historic $5.1M fine; NY civil court imposes $1M settlement. |
| 2024 | LobbyMatic exposed as fraud run under pseudonyms "Jay Klein" & "Bill Sanders"|
| 2024 | $300,000 retainer accepted from indicted $65M crypto-hacker for pardon. |
| 2025 | IRIS C2 launched; marketing offensive exploits and high-dollar zero-days. |
+------+----------------------------------------------------------------------------+
Financial Misconduct and Unregistered Securities (2015–2019)
Jacob Wohl gained public visibility as a teenager, dubbing himself the "Wohl of Wall Street" and appearing on financial news networks to promote his hedge funds. That financial apparatus quickly unraveled:

- 2017: The Arizona Corporation Commission found Wohl and his investment vehicles guilty of 14 counts of securities fraud, ordering him to pay $35,000 in restitution.
- 2019: Wohl pleaded guilty in California to four felony counts of selling unregistered securities, receiving two years of probation.
Fabricated Intelligence and Political Smear Operations (2018–2020)
Partnering with Washington lobbyist Jack Burkman (founder of Burkman & Associates), Wohl shifted toward political trickery, creating fictitious entities to stage elaborate press conferences.
- Surefire Intelligence: The pair established a front entity called "Surefire Intelligence," using stock photos and fake profiles for its alleged operatives. The firm attempted to orchestrate false sexual misconduct allegations against Special Counsel Robert Mueller.
- Targeted Campaigns: Similar fabricated allegations and staged press conferences were launched against Mayor Pete Buttigieg, Senator Elizabeth Warren, and then-presidential candidate Kamala Harris.
Robocall Disinformation and Unprecedented Regulatory Fines (2020–2023)
In the lead-up to the 2020 U.S. presidential election, Wohl and Burkman executed a massive, illegal robocall campaign aimed at suppressing voter turnout in minority neighborhoods across battleground states, including Michigan, Ohio, and Pennsylvania. The automated calls falsely claimed that voting by mail would land citizens in a public database used by law enforcement to execute warrants and collect debts.
- Criminal Convictions: The pair faced a 15-count felony indictment in Cleveland, Ohio. In 2022, both pleaded guilty to telecommunications fraud, receiving sentences of probation, community service, and monetary fines. Exhaustive legal appeals were ultimately rejected, cementing their felony records in late 2025.
- Civil Rights Settlement: In March 2023, a federal judge in New York ruled that the pair violated federal and state civil rights statutes, resulting in a $1 million settlement.
- FCC Sanctions: In June 2023, the Federal Communications Commission (FCC) issued a $5.1 million fine against Wohl and Burkman—the largest penalty ever handed down under the Telephone Consumer Protection Act (TCPA).
Pseudonym Politics: The LobbyMatic AI Hoax (2023–2024)
Following their criminal convictions, the duo launched LobbyMatic, an alleged AI-powered lobbying platform. The venture unraveled in September 2024 when investigations revealed that Wohl and Burkman were running the firm using fake names—Wohl as "Jay Klein" and Burkman as "Bill Sanders." Multiple employees resigned upon discovering the true identities and felony histories of their leadership.
Crypto-Hacker Retainers (2024)
According to investigative reporting by journalist Molly White, Wohl and Burkman accepted a $300,000 retainer in early 2024 from an indicted Canadian cryptocurrency hacker accused by federal prosecutors of stealing $65 million from the KyberSwap and Indexed Finance platforms. The duo was retained to secure a presidential pardon for the unconvicted fugitive.
Operational Metrics and the IRIS C2 Ecosystem
IRIS C2 represents the pair’s foray into offensive cyber capabilities. Emerging online in early 2025, the company utilizes aggressive social media marketing to cultivate an image of a high-tech intelligence contractor.

+-------------------------------+
| CALVEXA GROUP LLC |
| (Registered Contractor Front)|
+---------------+---------------+
|
v
+-------------------------------+
| IRIS C2 |
| (irisc2[.]com / @C2IRIS) |
+---------------+---------------+
|
+-------------------+-------------------+
| |
v v
+---------------------------+ +---------------------------+
| Zero-Day Exploits Market | | Government Contracting |
| Payouts: $10K - $7.0M | | Claims: Phone Hacking |
+---------------------------+ +---------------------------+
Corporate Structure and Physical Locations
Corporate lookup tools and government contracting registries link irisc2[.]com directly to Calvexa Group LLC, an entity registered in Virginia.
- Corporate Address: Calvexa Group LLC lists an address in Arlington, Virginia, which is the private residence and office space of 60-year-old Jack Burkman.
- Public Outreach: IRIS C2 maintains an active account on X (formerly Twitter) under the handle @C2IRIS, which has accumulated over 4,000 followers since its creation in January 2025.
- Physical Recruitment: Attendees at regional cybersecurity conferences reported that Wohl personally solicited security researchers in mid-2025, attempting to acquire vulnerability code directly from developers.
Zero-Day Payout Scale and Recruitment Metrics
IRIS C2 publicizes a pay scale designed to rival established exploit brokers like Zerodium and Crowdfense:
| Target Category | Scope & Capability | Advertised Payout Range |
|---|---|---|
| Low-Tier Flaws | Individual primitives, partial chains | $10,000 – $100,000 |
| Mid-Tier Exploits | Mobile/Desktop OS privilege escalation | $100,000 – $1,000,000 |
| High-Tier Capabilities | Zero-click remote code execution (RCE) | $1,000,000 – $7,000,000 |
To attract talent, the company specifically targets young hackers, explicitly stating on social media:
"Our business model is this: Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience."
Official Statements and Claims vs. Reality
When confronted by journalists regarding the true leadership and operational security of IRIS C2, Wohl and Burkman offered conflicting narratives.

Executive Statements and Interview Account
When approached at his Arlington property, Jack Burkman declined to answer detailed questions, referring all operational inquiries to Jacob Wohl.
In an interview, Jacob Wohl made several assertions regarding his technical expertise and the company’s internal operations:
- Operational Role: Wohl claimed Burkman is not involved in the day-to-day management of IRIS C2.
- Core Product Line: He stated the business shifted from traditional penetration testing to focus exclusively on selling specialized phone-hacking capabilities to federal agencies.
- Self-Taught Expertise: Admitting to having no formal training, computer science degrees, or certifications, Wohl asserted:
"I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."
Reality vs. Disseminated Claims
+------------------------------------+---------------------------------------------------+
| IRIS C2 / Wohl Assertions | Documented Investigative Reality |
+------------------------------------+---------------------------------------------------+
| Active federal government contracts| Zero active direct awards listed on SAM/G2Xchange |
| ~40 full-time security employees | Zero profiles on LinkedIn; historical pseudonyms |
| Legitimate exploit development | History of unfulfilled claims, scams & hoaxes |
| Self-taught top-tier tech expert | No formal CS background; past securities fraud |
+------------------------------------+---------------------------------------------------+
- Government Contracting Status: While federal databases like G2Xchange confirm Calvexa Group LLC is registered as a potential government contractor, public procurement data shows no record of any active or historic federal contracts awarded to the company.
- The 40 "Invisible" Employees: Wohl claimed IRIS C2 employs roughly 40 personnel who are prohibited from disclosing their employment on platforms like LinkedIn due to strict operational security. However, given the pair’s history with LobbyMatic—where staff were recruited without knowing their bosses were operating under pseudonyms—cybersecurity analysts express skepticism that this workforce exists.
Future Outlook and Risk Analysis for the Cybersecurity Market
The entry of convicted fraudsters into the zero-day market highlights a growing risk in the offensive security ecosystem. Unlike traditional defense contracting—which involves rigorous background checks, security clearances, and supply chain vetting—the private exploit broker market often relies on anonymity and non-disclosure agreements.
Industry Risks
- Financial Risk for Vulnerability Researchers: Independent researchers who submit zero-day exploits to unverified brokers risk IP theft, non-payment, or breach of non-disclosure agreements. Given Wohl’s past convictions for financial fraud and failure to pay court-ordered penalties, researchers face severe counterparty risk.
- Burned Exploits and Legal Exposure: Exploits turned over to unauthorized or unvetted entities may be mishandled, leaked, or resold to unauthorized third parties, exposing researchers to potential civil or criminal liabilities under laws like the Computer Fraud and Abuse Act (CFAA).
- Regulatory Scrutiny: Regulatory bodies, including the U.S. Department of Commerce’s Bureau of Industry and Security (BIS), strictly control the export of cybersecurity items and dual-use technologies. Entities attempting to trade offensive cyber tools without proper compliance protocols risk immediate federal intervention.
As IRIS C2 continues its online push for high-value vulnerabilities, the cybersecurity community is urging extreme caution. Analysts advise that researchers perform due diligence, verify corporate registrations, and avoid dealing with brokers operated by unvetted figures using pseudonyms or hiding behind shell companies.
