The High-Stakes Mirage: Inside the Cybersecurity Startup Run by Notorious Political Operatives

In the shadowy world of “zero-day” vulnerabilities—previously unknown security flaws that can compromise the world’s most popular software—there is a strict hierarchy of trust. Typically, this market is populated by vetted government contractors, elite academic researchers, and established cybersecurity firms. However, a new player has emerged in McLean, Virginia, that is shattering the industry’s norms of discretion.
IRIS C2, a startup promising million-dollar payouts for high-level exploits, has gained over 4,000 followers on X (formerly Twitter) since its launch in early 2025. While the company markets itself as a cutting-edge provider of offensive cybersecurity capabilities, an investigation reveals a far more volatile reality: the company is the latest venture by Jacob Wohl and Jack Burkman, two disgraced political operatives with a long, documented history of fraud, identity theft, and far-right conspiracy mongering.
The IRIS C2 Pitch: Million-Dollar Promises
The business model of IRIS C2 is as brazen as it is unconventional. Through its social media presence and website, irisc2[.]com, the firm actively recruits junior engineers, explicitly stating that it prioritizes "raw talent" and "high IQ" over formal degrees or industry experience.
The company’s public-facing marketing is designed to attract top-tier exploit developers with the promise of lucrative compensation. According to their website, IRIS C2 is actively acquiring "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms." The site lists a staggering range of potential payouts: from $10,000 for minor findings to a cool $7 million for high-value, reliable exploits.
This outreach has been aggressive. According to reports from regional cybersecurity conferences, representatives linked to the firm have been seen actively pestering researchers to sell their private findings, a practice described by industry veterans as highly unusual and remarkably unprofessional for an outfit claiming to handle sensitive government-grade capabilities.

A History of Deception: The Wohl-Burkman Chronology
To understand the skepticism surrounding IRIS C2, one must look at the long, litigious, and often bizarre history of its operators. The duo of Jack Burkman, 60, and Jacob Wohl, 28, has spent nearly a decade orchestrating schemes that blur the lines between political activism and criminal enterprise.
2015–2019: The "Wohl of Wall Street" Era
Jacob Wohl first gained notoriety as a teenager, branding himself "Wohl of Wall Street" while appearing on cable news to discuss hedge funds. That persona collapsed in 2017 when the Arizona Corporation Commission charged him with securities fraud. In 2019, he pleaded guilty in California to four felony counts related to the sale of unregistered securities, receiving two years of probation.
2018–2020: The Fabrication Campaign
During the peak of the Trump-era political polarization, the duo became notorious for "intelligence" operations that were consistently exposed as fraudulent. They were linked to:
- The Mueller/Buttigieg Smears: Attempting to frame then-FBI Director Robert Mueller and presidential candidate Pete Buttigieg with fabricated sexual assault allegations.
- Political Hit Jobs: Holding press conferences to promote baseless, scandalous claims against Senator Elizabeth Warren and Kamala Harris.
2020–2025: The Legal Reckoning
The pair’s most significant legal trouble arose from their role in a 2020 robocall scheme aimed at suppressing the Black vote in Detroit. The operation led to multiple indictments. In late 2025, following a series of failed appeals, both men were sentenced to probation for 15 felony counts in Ohio.
Prior to this, in 2023, they were hit with a record-breaking $5.1 million fine by the Federal Communications Commission (FCC) for their illegal robocall campaigns—the largest penalty ever sought by the agency under the Telephone Consumer Protection Act. Additionally, a New York civil court judge ordered them to pay a $1 million settlement for violating federal and state civil rights laws.

The Shell Game: From LobbyMatic to IRIS C2
IRIS C2 is not the first time the duo has attempted to enter the professional services market under the cover of a tech-forward company. In 2024, Politico exposed their short-lived venture, LobbyMatic, an AI-based lobbying platform.
The duo operated LobbyMatic using pseudonyms: Wohl went by "Jay Klein," while Burkman used the moniker "Bill Sanders." The facade was so effective that employees were hired under false pretenses. The operation unraveled when staff discovered their true identities, leading to mass resignations. IRIS C2 appears to be a spiritual successor to this strategy, utilizing the Calvexa Group LLC as a corporate veil. While Calvexa is registered as a federal contractor, it has no record of holding direct government contracts, casting significant doubt on the firm’s claims of providing "offensive capabilities" to the state.
The Professional Implications: Cybersecurity as a Facade
In the cybersecurity industry, the market for vulnerabilities is intentionally opaque. Legitimate "brokerage" firms work in high-security, low-visibility environments to prevent exploits from falling into the hands of malicious actors.
IRIS C2, by contrast, acts as a "clout-chaser" in a space that demands extreme discretion. The danger is not merely that the company may be a fraud; it is that it may be a honeypot or a data-mining operation. By advertising massive payouts, the firm may be successfully harvesting, or at least attempting to harvest, dangerous software vulnerabilities from unsuspecting researchers.
When interviewed by KrebsOnSecurity, Wohl dismissed concerns regarding his lack of formal training. "I know more about tech than anyone," Wohl claimed, describing his background as "extremely technical." He further alleged that the company has a staff of 40, though he insisted that none of them are permitted to list their employment on LinkedIn due to "operational security"—a convenient excuse that shields the company from external verification.

The "Pardon" Brokerage
The latest development in the pair’s trajectory suggests their interests may extend far beyond cybersecurity. According to reporting by journalist Molly White, Wohl and Burkman were paid a $300,000 retainer by a Canadian cryptocurrency fraudster. The accused, who is wanted internationally for the theft of $65 million from platforms like KyberSwap, reportedly hired the duo to lobby for a presidential pardon.
This revelation paints a picture of a business model that is less about software engineering and more about positioning themselves as fixers for high-net-worth individuals in legal jeopardy, utilizing their self-styled "tech" and "intelligence" ventures as a platform to gain influence.
Conclusion: A Warning to the Research Community
The existence of IRIS C2 serves as a cautionary tale for the cybersecurity research community. The allure of large payouts can be blinding, especially for junior researchers eager to make their mark. However, the operational history of its founders—marked by serial deception, federal fines, and a documented pattern of using corporate entities to facilitate political and personal agendas—suggests that IRIS C2 is a firm built on a foundation of sand.
As of this writing, there is no evidence that IRIS C2 possesses any of the "exquisite capabilities" it claims to sell. For the legitimate security community, the message is clear: the history of Jacob Wohl and Jack Burkman is not one of technological innovation, but one of exploitation. Any researcher engaging with the firm is doing so at the risk of their professional reputation, their security findings, and their legal standing.
