The Shadow Brokers of the Beltway: How Far-Right Conspiracy Theorists Jacob Wohl and Jack Burkman Infiltrated the Offensive Cybersecurity Market

Share
The Shadow Brokers of the Beltway: How Far-Right Conspiracy Theorists Jacob Wohl and Jack Burkman Infiltrated the Offensive Cybersecurity Market

Executive Overview

The high-stakes, opaque underworld of zero-day vulnerability trading has long attracted an eclectic mix of academic researchers, elite cryptographers, intelligence contractors, and opportunistic mercenaries. However, the ecosystem has recently been disrupted by an unexpected and deeply controversial entrant: IRIS C2, a Virginia-based startup aggressively dangling multi-million-dollar payouts for high-value software exploits.

While the firm’s public posture mimics that of a cutting-edge boutique offensive security provider—recruiting elite "raw talent" without regard for traditional academic credentials and dangling rewards ranging from $10,000 to $7 million—an investigative deep-dive reveals a startling reality. IRIS C2 is not spearheaded by seasoned veterans of the National Security Agency or elite red-team operators. Instead, it is run by Jacob Wohl and Jack Burkman, a pair of notorious far-right conspiracy theorists, convicted felons, and serial fraudsters whose past ventures include fake intelligence agencies, fraudulent securities schemes, massive voter-suppression robocall operations, and pseudonymous AI lobbying platforms.

Operating through shell companies like Calvexa Group LLC and maintaining a rapidly growing presence on X (formerly Twitter), Wohl and Burkman have pivoted from political dirty tricks and disinformation campaigns to the lucrative and sensitive realm of cyber warfare. This convergence of political charlatanism and offensive cyber capabilities raises acute national security concerns, highlighting the glaring lack of oversight and credential verification in the multi-billion-dollar government contracting and vulnerability brokerage pipeline.


Detailed Chronology: From Political Sabotage to Cyber Exploits

The trajectory of IRIS C2 cannot be understood without examining the long, bizarre, and legally troubled partnership between Jacob Wohl and Jack Burkman. Over the past decade, the duo has transitioned from fringe political lobbying to orchestrating coordinated disinformation campaigns, culminating in criminal prosecutions, massive civil liabilities, and now, a foray into zero-day exploit brokerage.

The Early Years and Securities Fraud

Jacob Wohl’s journey into notoriety began early. By the age of 17, he had established several investment funds, earning self-promotion as the "Wohl of Wall Street" after a 2015 appearance on Fox News. However, the veneer quickly cracked. In 2017, the Arizona Corporation Commission charged Wohl and his investment vehicles with 14 counts of securities fraud, ordering him to pay $35,000 in restitution. This was followed in 2019 by a criminal guilty plea in California to four felony counts of selling unregistered securities, netting him two years of probation.

Political Dirty Tricks and Fabricated Scandals

With his financial career effectively sidelined, Wohl partnered with Jack Burkman—a 60-year-old Arlington, Virginia-based lobbyist—to form a partnership centered on political provocation and manufactured scandals. Between 2018 and 2020, the pair became infamous for staging elaborate, short-lived press conferences designed to frame public figures.

Their targets included high-profile Democratic politicians and national security officials. They attempted to peddle fabricated sexual assault allegations against then-FBI Director Robert Mueller and Pete Buttigieg, then-mayor of South Bend, Indiana, and a presidential candidate. In 2019, they held press conferences falsely alleging extramarital affairs by Senator Elizabeth Warren and then-candidate Kamala Harris. These operations relied on shell entities styled as intelligence and investigative firms, setting a template for future deceptions.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Voter Suppression and Massive Federal Penalties

The pair’s activities turned severely criminal in the wake of the 2020 U.S. presidential election. Wohl and Burkman orchestrated a widespread robocall campaign across crucial battleground states, disseminating false claims regarding mail-in ballots designed to suppress voter turnout.

  • The Cleveland Indictment: Prosecutors in Ohio indicted the pair on 15 felony counts for orchestrating a robocall scheme specifically aimed at suppressing the Black vote in Detroit. After unsuccessful legal challenges to dismiss the charges, both Wohl and Burkman were sentenced to probation in late 2025.
  • Telecommunications Fraud: In 2022, they pleaded guilty to a single felony count of telecommunications fraud in Ohio, drawing fines, probation, and mandatory community service.
  • Civil Rights Liability: A New York federal court ruled in March 2023 that Wohl and Burkman had violated federal and state civil rights laws, resulting in a staggering $1 million civil settlement.
  • FCC Record Fine: In June 2023, the Federal Communications Commission (FCC) levied a $5.1 million fine against the pair—the largest penalty ever sought by the agency under the Telephone Consumer Protection Act—for their illicit robocall campaigns.

The AI Lobbying Pseudoscience: LobbyMatic

Before pivoting to cybersecurity, Wohl and Burkman attempted to capitalize on the artificial intelligence boom. In late 2023 and 2024, they operated LobbyMatic, an AI-based political lobbying platform. According to an investigative report by Politico, the pair ran the company under assumed names—Wohl used the pseudonym "Jay Klein," while Burkman operated as "Bill Sanders."

The charade collapsed when employees discovered the true identities of their bosses, leading to immediate resignations. The venture quietly dissolved, clearing the runway for their next reinvention: offensive cyber-intelligence.

The Crypto Pardon Retainer

Further compounding their post-political endeavors, a March 2025 report by investigative journalist Molly White revealed that Wohl and Burkman had accepted a $300,000 retainer from a Canadian cryptocurrency fraudster wanted by the United States and international law enforcement. The fugitive, accused of orchestrating $65 million hacks against crypto platforms KyberSwap and Indexed Finance, allegedly hired the duo to secure a presidential pardon—an effort that ultimately failed to shield him from federal prosecution.


Supporting Context & Metrics: The Mechanics of IRIS C2

In January 2025, the entities transformed once more. Launching an X (Twitter) account under the handle @C2IRIS and branding themselves as IRIS C2, the duo established a digital storefront based in McLean, Virginia. Within months, the account amassed over 4,000 followers, broadcasting commentary on software exploits, artificial intelligence, and offensive security operations.

Corporate Structure and Shell Entities

Government contracting databases, including g2exchange.com, reveal that the domain irisc2.com is operated by a Virginia-registered entity named Calvexa Group LLC. The contact page for Calvexa Group redirects directly to the IRIS C2 portal. Incorporation records trace Calvexa Group’s Arlington, Virginia address to a property occupied by Jack Burkman.

Despite registering as a federal contractor, G2Exchange records indicate that Calvexa Group holds no active, direct federal prime or subcontracts—suggesting the registration may serve as a veneer of legitimacy to attract talent or position the firm for future procurement opportunities.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Recruiting Talent and Exploitation Pricing

IRIS C2’s business model relies on bypassing traditional corporate human resources pipelines to capture undervalued, highly skilled engineering talent. A pinned post on the IRIS C2 X account outlines their philosophy:

"Our business model is this: Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience."

The firm’s public pricing tiers, advertised widely across LinkedIn and X, span from $10,000 to $7 million, depending on the target software, execution reliability, and operational intelligence value of the asset. The catalog targets major consumer platforms, seeking zero-day exploits, individual primitives, and complete execution chains.


Official Statements and Investigative Interviews

When confronted by security journalist Brian Krebs regarding the operations of IRIS C2, Jacob Wohl sought to distance his partner while defending the firm’s capabilities.

Wohl’s Defense and Technical Claims

According to Wohl, Jack Burkman maintains no active role in the day-to-day operations of IRIS C2. Wohl claimed the venture initially functioned as a traditional penetration testing firm before pivoting toward the lucrative market of supplying phone-hacking and mobile-exploitation capabilities to government clients.

When pressed on specific federal contracts, Wohl invoked national security discretion, stating he was "not at liberty to speak publicly" about his agency clients. Notably, Wohl admitted he possesses no formal education, academic training, or professional certifications in computer science or cybersecurity, asserting instead that his expertise is entirely self-taught.

"I know more about tech than anyone," Wohl boasted during the interview. "My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Refining Exploit Primitives

Wohl offered a glimpse into how the startup acquires its intellectual property, explaining that vulnerability researchers frequently bring raw, unpolished findings to the firm.

"Let’s say someone finds a flaw in a media decoder on a phone," Wohl explained. "A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do."

Operational Security and Internal Deception

Wohl claimed that IRIS C2 employs approximately 40 individuals. However, in a stark echo of their previous ventures, Wohl noted that none of these purported employees are permitted to list their employment on professional networks like LinkedIn for "operational security reasons." This dynamic mirrors the deception uncovered at LobbyMatic, where employees operated under false assumptions about corporate leadership. Indeed, public statements from the IRIS C2 X account in May noted that the account manager’s romantic partner had no idea what he did for a living—highlighting a corporate culture steeped in secrecy, obfuscation, and potential self-delusion.


Future Outlook: Risks to the Vulnerability Ecosystem

The emergence of IRIS C2 underscores systemic vulnerabilities within the offensive cyber-intelligence market. While established vulnerability brokers (such as Zerodium, Crowdfense, and various defense primes) enforce rigorous vetting procedures, compliance frameworks, and technical validation mechanisms, the low barrier to entry in digital space allows bad actors with track records of fraud to establish storefronts in the gray market.

Key systemic risks moving forward include:

  1. Exploitation of Junior Researchers: By targeting young, self-taught programmers with promises of million-dollar payouts, firms like IRIS C2 may inadvertently or intentionally draw vulnerable talent into legally and ethically perilous transactions, potentially violating international arms export regulations (such as ITAR) or domestic anti-hacking laws.
  2. Federal Procurement Vulnerabilities: The ease with which convicted felons can establish federal contracting shells (such as Calvexa Group LLC) reveals glaring loopholes in government vendor vetting protocols, posing risks to agency supply chains.
  3. Reputational Damage to the Security Industry: The crossover of far-right political operatives and conspiracy theorists into vulnerability research threatens to delegitimize legitimate bug-bounty and zero-day acquisition programs, inviting increased regulatory scrutiny and legislative crackdowns on vulnerability research.

As cybersecurity researchers and federal investigators continue to monitor the digital footprint of IRIS C2 and Calvexa Group, the episode serves as a sobering reminder: in the digital gold rush of the 21st century, the line between high-tech innovation and sophisticated grift has never been thinner.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *