Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • Uncategorized
  • Krebs On Security
  • Felons, Fraudsters Flog Offensive Cybersecurity Startup
  • Krebs On Security

Felons, Fraudsters Flog Offensive Cybersecurity Startup

BrianKrebs Published: July 8, 2026 | Updated: August 31, 2026 6 min read
0 views

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

The IRIS C2 website dangles the possibility of million-dollar payouts for exploits to attract talent.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X. “Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience.”

The website linked in that profile — irisc2[.]com — says the company is hiring for a number of open positions, and a recent post on its LinkedIn page enthuses about an overwhelming number of applications from potential employees. The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value.”

The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based in Virginia called Calvexa Group LLC. The “contact” link on the website for Calvexa Group — calvexagroup[.]com — forwards visitors to irisc2[.]com. G2Exchange shows that while Calvexa Group LLC is registered as a federal contractor, it does not appear to be working on any direct government contracts.

A search on the Arlington, Va. address listed in the incorporation records for Calvexa Group LLC finds the property is occupied by Jack Burkman, the 60-year-old founder and managing partner of the lobbying firm Burkman & Associates. When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

Jack Burkman (left) and Jacob Wohl, at a press conference in August 2020. Image: Wikipedia.

Burkman and Wohl have a storied history of creating fake intelligence companies and using them to spread false claims about and frame public figures, including fabricated sexual assault claims against then FBI director Robert Mueller, and Pete Buttigieg, then mayor of South Bend, Indiana and a Democratic candidate for the presidency. In 2019, Burkman and Wohl held press conferences falsely alleging extramarital affairs by Sen. Elizabeth Warren (D-Mass.) and then-2020 presidential candidate Kamala Harris.

In the wake of the 2020 presidential election, Wohl and Burkman were prosecuted by multiple U.S. states for making thousands of robocalls to residents of battleground states and disseminating false claims about mail-in ballots. They were indicted in Cleveland on 15 felony counts of orchestrating a robocall scheme aimed at suppressing the black vote in Detroit, and were sentenced in late 2025 to probation after their appeals to dismiss the charges were rejected.

In 2022, Wohl and Burkman both pleaded guilty to a single felony charge of telecommunications fraud in Ohio, and sentenced to a fine, probation, and community service. In March 2023, a judge in a New York civil case ruled that Wohl and Burkman had violated federal and state civil rights laws, and the two agreed to pay a $1 million settlement.

In June 2023, the Federal Communications Commission (FCC) imposed a $5.1 million fine against Wohl and Burkman for their robocall campaigns, at the time the largest fine ever sought by the FCC under the Telephone Consumer Protection Act.

Jacob “Jay” Wohl’s GitHub account.

By the age of 17, Wohl had started multiple investment firms, and cultivated the nickname “Wohl of Wall Street” after appearing on Fox News in 2015 to discuss his new hedge funds. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, and ordered him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities and was sentenced to two years of probation.

The market for previously unknown security vulnerabilities has always been populated by a colorful mix of researchers, academics, charlatans, clout-chasers and people actively involved in cybercrime communities. But the market for selling offensive security services to the U.S. government tends to be far more circumspect. Plenty of government contractors recruit vulnerability researchers and pay for the exclusive rights to novel software exploits, yet none of them do so quite as brazenly and openly as IRIS C2.

Recent posts from the Twitter/X account IRISC2 (@c2iris).

Indeed, KrebsOnSecurity was unaware of IRIS C2 until last month, when an attendee at a regional cybersecurity conference shared that Wohl and Calvexa Group were pestering people at the conference about selling their vulnerability research.

In an interview with KrebsOnSecurity, Wohl said Mr. Burkman was not involved in the day-to-day operations of IRIS C2. Wohl shared that IRIS C2 originally began as a penetration testing company, but shifted its focus recently to selling phone-hacking services to the government. Several times throughout the interview, Mr. Wohl mentioned working on federal government contracts, but when pressed for specifics said he was not at liberty to speak publicly about them.

Mr. Wohl said he does not have any formal education or training in computer science or information security, and that most of his knowledge on the matter is self-taught.

“I know more about tech than anyone,” Wohl bragged. “My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin.”

Wohl said security researchers bring the company unique vulnerability findings “on a regular basis,” but that in many cases those findings are preliminary and not fully fleshed-out.

“Let’s say someone finds a flaw in a media decoder on a phone,” Wohl said. “A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do.”

Wohl claims IRIS C2 has approximately 40 employees, although he said none of them are allowed to list their employment on LinkedIn for operational security reasons. In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living. But if IRIS C2 has any other employees, they may be similarly unaware of Mr. Wohl’s history of outright fabrications — or even his real name.

In September 2024, Politico reported that Burkman and Wohl were bragging about big companies supposedly buying services from their now-defunct company LobbyMatic, which claimed to use artificial intelligence to assist in political lobbying efforts. However, Politico found the pair were running the company using pseudonyms, with Wohl reportedly adopting the name “Jay Klein” and Burkman using the moniker “Bill Sanders.” Politico reported that two of the former LobbyMatic employees resigned after learning of their true identities, while other employees only learned after they had left the company.

Update, July 9, 9:44 a.m. ET: Several readers pointed our attention to a March 31 publication from journalist Molly White, which reported that Burkman and Wohl were paid a $300,000 retainer by a Canadian cryptocurrency fraudster wanted by the United States and several other countries for allegedly stealing $65 million from the crypto platforms KyberSwap and Indexed Finance. According to that report, the two were hired to pursue a “presidential pardon to avert a miscarriage of justice” on behalf of the accused hacker, who has not yet been convicted.

About The Author

BrianKrebs

See author's posts

Original post here

What do you feel about this?

  • Krebs On Security

Post navigation

Previous: FBI Seizes NetNut Proxy Platform, Popa Botnet
Next: Lessons Learned from CISA’s Recent GitHub Leak

Author's Other Posts

FBI Probes Service Selling 153M+ Drivers Licenses nexus-phegseth.png

FBI Probes Service Selling 153M+ Drivers Licenses

September 1, 2026 0 0
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

August 31, 2026 0 0
Who’s Tracking You? Use This New Service to Find Out decryptads-ESPN.png

Who’s Tracking You? Use This New Service to Find Out

August 31, 2026 0 0
Microsoft Plugs Nearly 400 Security Holes workingonpc.png

Microsoft Plugs Nearly 400 Security Holes

August 31, 2026 0 0

Related Stories

nexus-phegseth.png
  • Krebs On Security

FBI Probes Service Selling 153M+ Drivers Licenses

BrianKrebs September 1, 2026 0 0
  • Krebs On Security

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

BrianKrebs August 31, 2026 0 0
decryptads-ESPN.png
  • Krebs On Security

Who’s Tracking You? Use This New Service to Find Out

BrianKrebs August 31, 2026 0 0
workingonpc.png
  • Krebs On Security

Microsoft Plugs Nearly 400 Security Holes

BrianKrebs August 31, 2026 0 0
moucka-surveillance.png
  • Krebs On Security

Canadian Man Pleads Guilty in Snowflake Extortions

BrianKrebs August 31, 2026 0 0
h96-amazon.png
  • Krebs On Security

Read This Before You Buy That TV Streaming Stick

BrianKrebs August 31, 2026 0 0

Trending Now

FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses 1

FBI Probes Service Selling 153M+ Drivers Licenses

September 1, 2026 0 0
FBI Probes Service Selling 153M+ Drivers Licenses nexus-phegseth.png 2

FBI Probes Service Selling 153M+ Drivers Licenses

September 1, 2026 0 0
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure jfrog.jpg 3

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

September 1, 2026 0 0
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems brazil.jpg 4

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

September 1, 2026 0 0

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses 1
  • Uncategorized

FBI Probes Service Selling 153M+ Drivers Licenses

September 1, 2026 0 0
FBI Probes Service Selling 153M+ Drivers Licenses nexus-phegseth.png 2
  • Krebs On Security

FBI Probes Service Selling 153M+ Drivers Licenses

September 1, 2026 0 0
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure jfrog.jpg 3
  • The Hacker News

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

September 1, 2026 0 0
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems brazil.jpg 4
  • The Hacker News

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

September 1, 2026 0 0
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds iphone.jpg 5
  • The Hacker News

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

September 1, 2026 0 0
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests iran-hacking.jpg 6
  • The Hacker News

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

September 1, 2026 0 0
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones click.jpg 7
  • The Hacker News

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

September 1, 2026 0 0

You may have missed

FBI Probes Service Selling 153M+ Drivers Licenses
  • Uncategorized

FBI Probes Service Selling 153M+ Drivers Licenses

Sean September 1, 2026 0 0
nexus-phegseth.png
  • Krebs On Security

FBI Probes Service Selling 153M+ Drivers Licenses

BrianKrebs September 1, 2026 0 0
jfrog.jpg
  • The Hacker News

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

[email protected] The Hacker News September 1, 2026 0 0
brazil.jpg
  • The Hacker News

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

[email protected] The Hacker News September 1, 2026 0 0
Copyright © 2026 All rights reserved. | MoreNews by AF themes.