A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

The IRIS C2 website dangles the possibility of million-dollar payouts for exploits to attract talent.
“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X. “Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience.”
The website linked in that profile — irisc2[.]com — says the company is hiring for a number of open positions, and a recent post on its LinkedIn page enthuses about an overwhelming number of applications from potential employees. The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value.”
The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based in Virginia called Calvexa Group LLC. The “contact” link on the website for Calvexa Group — calvexagroup[.]com — forwards visitors to irisc2[.]com. G2Exchange shows that while Calvexa Group LLC is registered as a federal contractor, it does not appear to be working on any direct government contracts.
A search on the Arlington, Va. address listed in the incorporation records for Calvexa Group LLC finds the property is occupied by Jack Burkman, the 60-year-old founder and managing partner of the lobbying firm Burkman & Associates. When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

Jack Burkman (left) and Jacob Wohl, at a press conference in August 2020. Image: Wikipedia.
Burkman and Wohl have a storied history of creating fake intelligence companies and using them to spread false claims about and frame public figures, including fabricated sexual assault claims against then FBI director Robert Mueller, and Pete Buttigieg, then mayor of South Bend, Indiana and a Democratic candidate for the presidency. In 2019, Burkman and Wohl held press conferences falsely alleging extramarital affairs by Sen. Elizabeth Warren (D-Mass.) and then-2020 presidential candidate Kamala Harris.
In the wake of the 2020 presidential election, Wohl and Burkman were prosecuted by multiple U.S. states for making thousands of robocalls to residents of battleground states and disseminating false claims about mail-in ballots. They were indicted in Cleveland on 15 felony counts of orchestrating a robocall scheme aimed at suppressing the black vote in Detroit, and were sentenced in late 2025 to probation after their appeals to dismiss the charges were rejected.
In 2022, Wohl and Burkman both pleaded guilty to a single felony charge of telecommunications fraud in Ohio, and sentenced to a fine, probation, and community service. In March 2023, a judge in a New York civil case ruled that Wohl and Burkman had violated federal and state civil rights laws, and the two agreed to pay a $1 million settlement.
In June 2023, the Federal Communications Commission (FCC) imposed a $5.1 million fine against Wohl and Burkman for their robocall campaigns, at the time the largest fine ever sought by the FCC under the Telephone Consumer Protection Act.

Jacob “Jay” Wohl’s GitHub account.
By the age of 17, Wohl had started multiple investment firms, and cultivated the nickname “Wohl of Wall Street” after appearing on Fox News in 2015 to discuss his new hedge funds. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, and ordered him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities and was sentenced to two years of probation.
The market for previously unknown security vulnerabilities has always been populated by a colorful mix of researchers, academics, charlatans, clout-chasers and people actively involved in cybercrime communities. But the market for selling offensive security services to the U.S. government tends to be far more circumspect. Plenty of government contractors recruit vulnerability researchers and pay for the exclusive rights to novel software exploits, yet none of them do so quite as brazenly and openly as IRIS C2.

Recent posts from the Twitter/X account IRISC2 (@c2iris).
Indeed, KrebsOnSecurity was unaware of IRIS C2 until last month, when an attendee at a regional cybersecurity conference shared that Wohl and Calvexa Group were pestering people at the conference about selling their vulnerability research.
In an interview with KrebsOnSecurity, Wohl said Mr. Burkman was not involved in the day-to-day operations of IRIS C2. Wohl shared that IRIS C2 originally began as a penetration testing company, but shifted its focus recently to selling phone-hacking services to the government. Several times throughout the interview, Mr. Wohl mentioned working on federal government contracts, but when pressed for specifics said he was not at liberty to speak publicly about them.
Mr. Wohl said he does not have any formal education or training in computer science or information security, and that most of his knowledge on the matter is self-taught.
“I know more about tech than anyone,” Wohl bragged. “My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin.”
Wohl said security researchers bring the company unique vulnerability findings “on a regular basis,” but that in many cases those findings are preliminary and not fully fleshed-out.
“Let’s say someone finds a flaw in a media decoder on a phone,” Wohl said. “A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do.”
Wohl claims IRIS C2 has approximately 40 employees, although he said none of them are allowed to list their employment on LinkedIn for operational security reasons. In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living. But if IRIS C2 has any other employees, they may be similarly unaware of Mr. Wohl’s history of outright fabrications — or even his real name.
In September 2024, Politico reported that Burkman and Wohl were bragging about big companies supposedly buying services from their now-defunct company LobbyMatic, which claimed to use artificial intelligence to assist in political lobbying efforts. However, Politico found the pair were running the company using pseudonyms, with Wohl reportedly adopting the name “Jay Klein” and Burkman using the moniker “Bill Sanders.” Politico reported that two of the former LobbyMatic employees resigned after learning of their true identities, while other employees only learned after they had left the company.
Update, July 9, 9:44 a.m. ET: Several readers pointed our attention to a March 31 publication from journalist Molly White, which reported that Burkman and Wohl were paid a $300,000 retainer by a Canadian cryptocurrency fraudster wanted by the United States and several other countries for allegedly stealing $65 million from the crypto platforms KyberSwap and Indexed Finance. According to that report, the two were hired to pursue a “presidential pardon to avert a miscarriage of justice” on behalf of the accused hacker, who has not yet been convicted.

Jacob Wohl should be in a prison cell. His level of being a POS is right up there with our dear leader snowflake Donny (who should also be in a prison cell)
Yep right next to spooky old Joe and Barry
Yup, most likely. And fairly nearby Pocahontas.
“dangling millions of dollars” — supposing such money exists, where do you suppose it’s coming from… ?
Jacob Wohl had approached me to work for him. It was obvious within minutes that this kid had no idea what he was talking about. He throws technical jargon around to seem impressive, yet lacks understanding of what goes on.
He has no money to even pay u lmao
Hang them high, they enable their customers to waste my time.
One of the “Customers” is currently using me for AI Quality Control
I get multiple calls a day (100’s in aggregate) from the same roofing survey which is very slow to learn No, I am not the Home Owner After a few weeks the AI works once in a while but I can’t say I’m pleased with the progress as they spoof the blocked numbers as well.
Brilliant founders and incredible marketing to win business from the current administration. Looking forward to hearing about their DHS contract win.
Nice burner.
Nice burner.
this is literally you jacob, get a job dude.
the first rule of fight club is you do not talk about fight club
1999 film came out before the saturation of social media self-advertisements. Selfie wasn’t really a thing yet.
I know, crazy right? What did regular people do all day? WORK?
Probably go to malls and work out of Orange Julius and Wendy’s locations in the food courts.
This sounds like a joke, but it actually isn’t. The main failing of this spurious company’s startup model is clearly more it is about 13 years past its business model’s peak. There is not much original about it, otherwise.
Start up the stock or offline influence version of boiler rooms or get taken by them, same as now. Note that doesn’t just mean stocks or crypto… I mean, the venues and products have changed, but this story is still the same PT Barnum stuff as the others, no?
I smell a pardon in their future.
This is easily the best Krebs report I have read in a while, and by best I mean documentation of truly horrible people who should be behind bars.
If we can’t get justice, at least expose the world to these crooks so they can be avoided…well as long as they use their real names.
“I know more about tech than anyone,” Wohl bragged.
That sounds familiar… Clearly all his problems with the law have not taught him any humility.
The only question that remains is how much damage will he sow before he is locked up. Tragically, I’m guessing plenty. “For they sow the wind, and they shall reap the whirlwind.” – Hosea 8:7
Thanks for shining a light on these evil men.
the odds on his receiving a pardon are such that it would seem pointless to make the wager.
straight scum baggin’ it bro!
did i mention that i know more about posting comments than anyone?
my therapist says the truth is i like to throw around a lot of copy and pasted ideas but I’ve little idea about what actually is going on… :*(**
Excellent work! Thank you for exposing these charlatans.
These men are anti-democratic actors and don’t represent ‘honest’ exploit brokers nor ethical security professionals.
Wondering if the regional conference is OffensiveCon in Berlin. He was there as well, not fitting in, approaching people randomly with annoying questions that showed he has no clue. Begging for cyber capabilities.
Annoying he´s been.
Approached me and others. …..
“I know more about tech than anyone,” Wohl bragged. “My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin.”
So we have another Trump but this one can make a complete sentance. Both should be in jail.
Brian, that headline – you’re not going to work for the NYPost, are you?
Fascinating long form article about these sorts of miscreants, thanks!
Brian – they’re going to use this to “disclose” exploits related to voting infrastructure in the 2026 election. Just calling it right here.
Excellent reporting. The larger issue is not simply one company or one set of personalities. It is the absence of a serious verification layer around offensive cyber claims, exploit acquisition, AI-enabled intelligence narratives, and government-facing contractor credibility.
When a company claims it can acquire or develop offensive capabilities, the burden of proof should be much higher than marketing language, claimed secrecy, or technical jargon.
Before researchers, agencies, contractors, investors, or policymakers engage, the questions should be basic:
Who owns and controls the entity?
Are claimed federal relationships real?
What legal authority governs the acquisition and use of exploits?
How are researchers protected?
Where do vulnerabilities come from?
Who can access the capability?
What prevents misuse, resale, leakage, or political targeting?
Who owns the downside if the claims are false or the tools cause harm?
Offensive cyber is not a normal startup category. It sits at the intersection of national security, public trust, law enforcement, intelligence, contractor oversight, and civil liberties.
Trust should not be granted because a company says it is operationally sensitive.
Trust the claim only after the control system is verified.
Thinking of Jeffrey Skilling, Enron’s CEO. A quote commonly attributed to Skilling is:
“If you have to ask how we make money, you’re too stupid to understand it.