A newly surfaced cybersecurity entity promising multi-million-dollar bounties for high-tier software vulnerabilities has raised alarm bells across the threat intelligence community. Operating under the name IRIS C2 and managed through a corporate entity called Calvexa Group LLC, the organization purports to purchase exclusive, high-grade offensive cyber capabilities—including zero-day exploits—for resale to government clients.
However, an investigation into the firm’s origin reveals that IRIS C2 is not run by seasoned defense contractors or veteran intelligence operatives, but by two of America’s most notorious far-right political operatives and convicted felons: Jacob Wohl and Jack Burkman.
[ CALVEXA GROUP LLC ]
│
▼
[ IRIS C2 STARTUP ]
(irisc2[.]com / @C2IRIS)
│
┌───────────────────────┴───────────────────────┐
▼ ▼
[ JACOB WOHL ] [ JACK BURKMAN ]
• Age 28 | "Wohl of Wall Street" • Age 60 | Burkman & Associates
• Convicted of Securities Fraud (2019) • Co-conspirator in Political Smears
• Convicted of Telecom Fraud (2022) • Convicted of Telecom Fraud (2022)
• Fined $5.1M by FCC (2023) • Fined $5.1M by FCC (2023)
Wohl, 28, and Burkman, 60, have spent the better part of a decade generating headlines through elaborate political hoaxes, fake intelligence fronts, illegal voter suppression schemes, and securities fraud. Their latest endeavor, IRIS C2, purports to operate out of Northern Virginia, dangling payouts between $10,000 and $7 million to recruit unvetted, high-IQ software researchers.
The emergence of convicted fraudsters attempting to act as middlemen for lethal cyber weapons poses significant risks to junior security researchers, government procurement channels, and the broader offensive security ecosystem.
Detailed Chronology: From Financial Smears to Cyber Warfare
The transition of Wohl and Burkman into the offensive security marketplace represents the latest chapter in a long history of deceptive corporate fronts and legal entanglements.
CHRONOLOGY OF KEY EVENTS
├─ 2015–2017 : Wohl launches financial firms; charged with securities fraud in Arizona.
├─ 2018–2019 : Wohl & Burkman orchestrate fake intelligence firms & political smear campaigns.
├─ 2019 : Wohl pleads guilty to felony securities fraud in California.
├─ 2020 : Pair orchestrates illegal battleground state robocall scheme targeting Black voters.
├─ 2022 : Both plead guilty to felony telecommunications fraud in Ohio.
├─ 2023 : FCC issues historic $5.1M fine; $1M civil rights settlement reached in NY.
├─ 2024 : Unmasking of LobbyMatic (AI lobbying firm using false names "Jay Klein" & "Bill Sanders").
├─ Early 2025 : $300k retainer accepted from fugitive crypto hacker; IRIS C2 launched.
└─ Late 2025 : Probation sentencing upheld following rejected legal appeals.
The Financial Fraud Era (2015–2019)
Jacob Wohl first gained public attention as a teenager, branding himself the "Wohl of Wall Street" during appearances on financial news networks to promote his hedge funds. That persona quickly unravelled:
2017: The Arizona Corporation Commission hit Wohl with 14 counts of securities fraud, ordering him to pay $35,000 in restitution.
2019: Wohl pleaded guilty in California to four felony counts of selling unregistered securities, receiving a sentence of two years’ probation.
The Disinformation and Political Hoax Era (2018–2020)
Partnering with Washington lobbyist Jack Burkman, founder of Burkman & Associates, Wohl pivoted to high-profile political smears using fictitious intelligence firms.
The duo held staged press conferences alleging fabricated sexual misconduct against public figures, including former FBI Director Robert Mueller, then-South Bend Mayor Pete Buttigieg, Senator Elizabeth Warren, and then-presidential candidate Kamala Harris.
Robocall Suppression and Historic Penalties (2020–2023)
Following the 2020 presidential election, Wohl and Burkman orchestrated a widespread robocalls campaign aimed at suppressing mail-in voting among Black voters in Detroit, Cleveland, and other key battleground areas.
Criminal Indictments: Indicted in Cleveland on 15 felony counts, both eventually pleaded guilty in Ohio to single felony counts of telecommunications fraud in 2022. Late in 2025, after their appeals were exhausted, their sentences of probation and community service were upheld.
Civil Rights Settlement: In March 2023, a federal judge in New York ruled that their robocall campaigns violated state and federal civil rights laws. The pair agreed to a $1 million settlement.
Record FCC Fine: In June 2023, the Federal Communications Commission (FCC) levied a $5.1 million fine against the duo—the largest fine ever imposed under the Telephone Consumer Protection Act (TCPA).
Pseudonymous AI Lobbying and Crypto Defense (2024–2025)
Before entering cybersecurity, Wohl and Burkman operated LobbyMatic, an AI-driven political lobbying platform.
A September 2024 investigation revealed that the pair managed LobbyMatic under false identities—Wohl adopted the pseudonym "Jay Klein," while Burkman went by "Bill Sanders." Key employees resigned upon discovering their employers’ real identities.
By early 2025, reports revealed that the pair had accepted a $300,000 retainer from a fugitive Canadian cryptocurrency hacker accused of stealing $65 million from Indexed Finance and KyberSwap, promising to lobby for a presidential pardon.
Launch of IRIS C2 (January 2025–Present)
In January 2025, the X (formerly Twitter) handle @C2IRIS was created, launching IRIS C2 into the offensive cyber arena. By mid-2025, the firm was actively soliciting researchers, pitching high payouts on social media, and directly approaching attendees at regional technical conferences.
Supporting Context & Metrics: Anatomy of the IRIS C2 Scheme
To understand the operational footprint of IRIS C2, it is necessary to examine its corporate backing, promotional claims, and how its public posture diverges from standard defense industry norms.
Data from the federal contracting portal G2Xchange links irisc2[.]com to Calvexa Group LLC, a entity incorporated in Virginia.
Corporate records trace Calvexa Group LLC to an address in Arlington, Virginia occupied by Jack Burkman.
While Calvexa Group is registered as a federal contractor, government records show no active or past direct federal contract awards.
Promised Exploit Bounties
On its website and social media channels, IRIS C2 advertises substantial payouts for original zero-day vulnerabilities across major operating systems and platforms:
[Target: Mobile OS / Decoders] ──► [Primitive / Partial Chain] ──► Bounties: $10K - $1M
[Target: Desktop / Enterprise] ──► [Full Zero-Click Chain] ──► Bounties: Up to $7M
IRIS C2 targets zero-day exploits, isolated execution primitives, partial exploit chains, and fully functional zero-click capabilities. However, established exploit brokers (such as Zerodium or Crowdfense) operate through rigorous vetting, institutional backing, and strict nondisclosure frameworks. IRIS C2’s open social media solicitation stands in contrast to established defense norms.
TRADITIONAL BROKERS vs. IRIS C2 MARKET APPROACH
Feature Traditional Exploit Brokers IRIS C2 (Calvexa Group)
─────────────────────────────────────────────────────────────────────────────
Vetting Rigorous KYC & background checks Open social recruitment
Public Stance Discreet, highly guarded Aggressive social posts
Key Personnel Vetted defense executives Convicted felons (aliases)
Target Talent Experienced researchers Junior/unaffiliated devs
Industry Presence Established agency contracts Zero verifiable contracts
Recruitment Strategy and "Ghost" Staffing
A pinned post on the IRIS C2 X account explicitly outlines the firm’s targeting strategy:
"Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience."
While Wohl claims that IRIS C2 employs approximately 40 workers, not a single employee publicly lists the firm as their employer on professional platforms like LinkedIn. Wohl attributes this discrepancy to strict "operational security" (OpSec)—a claim that mirrors the operational secrecy used during the LobbyMatic venture to hide leadership identities from staff.
Official Statements & Key Interventions
When confronted regarding the ownership and operational reality of IRIS C2, responses from both founders highlighted their ongoing operational dynamic.
Jack Burkman’s Response
When approached regarding the corporate filings of Calvexa Group LLC at his Arlington address, Jack Burkman declined to answer technical questions directly, referring all inquiries regarding IRIS C2 to his long-time associate, Jacob Wohl.
Jacob Wohl’s Assertions
In an interview, Jacob Wohl insisted that Burkman maintains no involvement in the day-to-day operations of IRIS C2. Wohl claimed that the enterprise initially launched as a penetration testing firm before shifting its focus to offensive mobile exploitation capabilities for government clients.
"I know more about tech than anyone. My background has always been extremely
technical, and I’ve always been deeply into tech. People know me as someone who
is able to create spectacularly exquisite capabilities that would make your
head spin."
— Jacob Wohl
When pressed on his technical background, Wohl acknowledged having no formal education or institutional training in computer science, software engineering, or information security, asserting that his expertise is entirely self-taught.
Regarding IRIS C2’s pipeline for zero-day acquisitions, Wohl stated:
"Let’s say someone finds a flaw in a media decoder on a phone. A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do."
Despite Wohl’s repeated assertions that IRIS C2 works on federal defense projects, official government procurement databases show no record of active prime contracts or subcontracts awarded to Calvexa Group LLC or IRIS C2.
Future Outlook & Industry Risk Assessment
The emergence of IRIS C2 highlights critical vulnerabilities within both the cybersecurity labor market and the national security vendor ecosystem.
RISK VECTORS CREATED BY IRIS C2
┌─────────────────────────────────────────────────────────────────┐
│ 1. Intellectual Property Theft / Unpaid Work │
│ Junior researchers risk submitting zero-days without payout.│
├─────────────────────────────────────────────────────────────────┤
│ 2. Proliferation of Zero-Days to Unvetted Buyers │
│ Exploits acquired could be resold on black markets. │
├─────────────────────────────────────────────────────────────────┤
│ 3. Legal and Counterintelligence Peril │
│ Researchers risk liability by dealing with convicted felons. │
└─────────────────────────────────────────────────────────────────┘
1. Peril for Independent Vulnerability Researchers
By specifically targeting young, degree-less coders with promises of million-dollar payouts, IRIS C2 targets talented individuals who may lack legal resources or awareness of Wohl and Burkman’s history. Vulnerability researchers who submit working code or partial primitives to unvetted entities risk having their intellectual property misappropriated without compensation.
2. Proliferation and Counterintelligence Vulnerabilities
In the offensive security industry, handling zero-day exploits requires strict adherence to legal standards and export control regulations (such as ITAR and the Wassenaar Arrangement). An unvetted broker operated by individuals with a history of fraud creates potential counterintelligence risks, including the potential leakage or unauthorized sale of zero-day exploits to unauthorized buyers or foreign adversaries.
3. Legal Consequences and Heightened Regulatory Scrutiny
Given Wohl and Burkman’s ongoing probation terms, multi-million-dollar civil judgments, and record-setting FCC penalties, their business activities remain under active observation by civil rights groups, legal authorities, and federal regulators. Any misrepresentation regarding government contracting status or non-payment to researchers could trigger swift regulatory intervention.
Conclusion
IRIS C2 represents an unexpected convergence of political disinformation, financial fraud, and offensive cyber capabilities. As the firm continues its public push to recruit young talent, the cybersecurity community and government procurement authorities face the challenge of insulating vulnerable researchers and defense supply chains from actors with a documented history of fraud.