The Illusion Factory’s Next Act: How Jacob Wohl and Jack Burkman Hijacked the Zero-Day Market with IRIS C2

Share
The Illusion Factory’s Next Act: How Jacob Wohl and Jack Burkman Hijacked the Zero-Day Market with IRIS C2

Executive Overview

The high-stakes ecosystem of cybersecurity vulnerability research—a shadow economy populated by elite code-breakers, institutional brokers, defense contractors, and state-backed espionage units—prides itself on extreme discretion. Within this rarefied marketplace, software flaws are traded like precious commodities, and multimillion-dollar bids for pristine "zero-day" exploits are traditionally handled behind layers of strict confidentiality.

Yet, a newly emerged startup calling itself IRIS C2 has shattered these time-tested norms by brazenly advertising million-dollar payouts on social media platforms like X (formerly Twitter) and LinkedIn. Operating out of McLean, Virginia, the entity dangles eye-watering financial rewards—ranging from $10,000 to $7 million—to attract top-tier vulnerability researchers, software engineers, and exploit developers. Their pitch specifically targets raw talent, explicitly stating that university degrees and traditional corporate resumes are entirely optional.

Beneath the veneer of an aggressive, unconventional offensive security boutique, however, lies a familiar enterprise. An investigative deep dive reveals that IRIS C2 is not spearheaded by seasoned cyber intelligence veterans or elite hackers. Instead, it is the latest commercial vehicle of Jacob Wohl and Jack Burkman: a notorious pair of far-right conspiracy theorists, convicted felons, and professional fraudsters whose careers have been defined by fabricated intelligence operations, electoral interference schemes, and pseudonymous corporate ventures.

Through a network of shell companies, including Calvexa Group LLC, Wohl and Burkman have pivoted from political dirty tricks and AI lobbying facades into the sensitive world of offensive cyber capabilities and phone-hacking services. This convergence of fringe political grifters and the lucrative zero-day vulnerability market highlights startling vulnerabilities in the oversight of federal contracting portals and raises critical alarms regarding the integrity of private-sector cyber procurement.


Detailed Chronology: From Electoral Sabotage to Cyber Exploits

To understand the alarming trajectory of IRIS C2, one must trace the timeline of its founders, whose past exploits read like a dark satire of modern political and financial corruption.

1. The Early Years and Financial Fraud

Jacob Wohl’s journey into notoriety began long before he entered the political arena. By the age of 17, he had established several pseudo-investment firms, cultivating the media-friendly moniker “Wohl of Wall Street” after securing an appearance on Fox News in 2015 to discuss his purported hedge funds. The facade quickly collapsed. In 2017, the Arizona Corporation Commission charged Wohl and his investment operations with 14 counts of securities fraud, ordering him to pay $35,000 in restitution. This was followed in 2019 by a guilty plea in California, where Wohl admitted to four felony counts of selling unregistered securities, earning himself a two-year sentence of probation.

2. The Era of Political Dirty Tricks and Fabricated Scandals

Partnering with older conservative lobbyist Jack Burkman, Wohl weaponized his penchant for deception against high-profile public figures. Throughout 2018 and 2019, the duo orchestrated a series of elaborate, short-lived "intelligence companies" designed to launch false claims and frame prominent politicians.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security
  • They fabricated sensational sexual assault allegations against then-FBI Director Robert Mueller and South Bend Mayor Pete Buttigieg during his 2020 presidential campaign.
  • They held bizarre press conferences falsely accusing Senator Elizabeth Warren and then-candidate Kamala Harris of extramarital affairs.

These stunts consistently collapsed under basic journalistic scrutiny, frequently resulting in public humiliation and legal liabilities. However, the pair’s actions soon escalated from absurd media spectacles to direct criminal interference in American democratic processes.

3. Voter Suppression and Landmark Federal Penalties

In the wake of the 2020 presidential election, Wohl and Burkman crossed a definitive legal threshold by executing a massive robocall campaign across key battleground states. The automated calls disseminated patently false claims regarding mail-in voting, designed explicitly to discourage minority voter participation.

Law enforcement agencies in multiple jurisdictions took notice:

  • Criminal Indictments: The pair was indicted in Cleveland on 15 felony counts for orchestrating a robocall scheme aimed at suppressing the Black vote in Detroit. After failed legal appeals to dismiss the charges, they were sentenced to probation in late 2025.
  • Guilty Pleas: In 2022, Wohl and Burkman pleaded guilty to a single felony charge of telecommunications fraud in Ohio, incurring fines, probation, and community service mandates.
  • Civil Judgments: In March 2023, a New York civil court judge ruled that the duo had flagrantly violated federal and state civil rights laws. They agreed to a staggering $1 million settlement.
  • Federal Communications Commission (FCC) Penalties: In June 2023, the FCC levied a historic $5.1 million fine against Wohl and Burkman for their illegal robocall operations—representing the largest fine ever sought by the agency under the Telephone Consumer Protection Act (TCPA).

4. The Pseudonymous AI Lobbying Pivot

Refusing to exit the business landscape despite their toxic public reputations, Wohl and Burkman adapted their tactics. In late 2024, investigative reporting by Politico exposed that the pair was running an artificial intelligence-powered lobbying platform named LobbyMatic. Operating under assumed aliases—with Wohl adopting the pseudonym "Jay Klein" and Burkman posing as "Bill Sanders"—they solicited major corporate clients while hiding their true identities. The scheme unraveled internally when several employees discovered their bosses’ real backgrounds, prompting immediate resignations.

5. Transition to the Cyber Underworld: IRIS C2

Following the collapse of LobbyMatic, the duo established Calvexa Group LLC in Virginia, which serves as the corporate parent for their latest endeavor: IRIS C2. Launched in January 2025, the enterprise quickly cultivated an online footprint via an X account (@C2IRIS) and a dedicated website (irisc2[.]com). By dangling million-dollar bounties for software exploits, the organization sought to tap into the lucrative talent pool of disillusioned or financially motivated vulnerability researchers, effectively bridging the gap between high-tech cyber mercenary work and the dark comedy of their past scams.


Supporting Context & Metrics: The Zero-Day Market vs. The Con Artists

The Economics of Software Vulnerabilities

The market for zero-day exploits—previously unknown software vulnerabilities that can be leveraged to compromise operating systems, browsers, or messaging applications—is fiercely competitive. Legitimate entities like Zerodium, Project Zero, and defense contractors acquire these flaws to patch systems or provide offensive capabilities to nation-state intelligence agencies. Payouts regularly reach millions of dollars depending on the target ecosystem (e.g., Apple iOS, Android, or Microsoft Windows) and the reliability of the exploit chain.

However, the ecosystem relies heavily on trust, technical competence, and verifiable cryptographic proof of concept. The entry of individuals with no formal computer science training, such as Jacob Wohl, introduces systemic volatility.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Key Metrics and Identifiers of the IRIS C2 Operation

Metric / Indicator Details
Founding Date January 2025 (X account creation and initial web launch)
Parent Entity Calvexa Group LLC (Registered federal contractor in Virginia)
Physical Address Arlington, VA property occupied by Jack Burkman
Stated Bounties $10,000 to $7,000,000 per exploit capability
X/Twitter Following Over 4,000 followers as of mid-2026
Regulatory Standing Active federal contractor registration with no recorded direct federal awards
Historical Penalties $5.1M FCC fine, $1M New York civil settlement, multiple felony convictions

The International Crypto Retainer Connection

Adding an even more precarious layer to their operations, a report published in March 2026 by investigative journalist Molly White revealed that Wohl and Burkman were paid a substantial $300,000 retainer by a Canadian cryptocurrency fraudster. The individual, currently wanted by the United States and international authorities for allegedly orchestrating $65 million in cyber hacks against platforms like KyberSwap and Indexed Finance, hired the pair to lobby for a presidential pardon to evade prosecution. This transaction underscores how Wohl and Burkman continue to monetize their proximity to political circles on behalf of transnational criminal actors.


Official Statements and Investigative Interviews

When confronted by security researchers and journalists, Jacob Wohl’s responses have oscillated between defiant technological braggadocio and vague corporate talking points.

During an interview with security journalist Brian Krebs, Wohl attempted to distance Jack Burkman from the daily management of IRIS C2, asserting that Burkman maintains no active role in the firm’s technical operations. According to Wohl, the company’s initial focus on standard penetration testing rapidly evolved into supplying mobile device-hacking capabilities to government clients.

When pressed regarding specific government contracts—a cornerstone of their pitch to prospective talent and clients—Wohl repeatedly demurred, stating he was "not at liberty to speak publicly" about classified or sensitive federal engagements.

Crucially, Wohl admitted that he possesses no formal education or professional background in computer science, software engineering, or information security, characterizing his entire technical expertise as self-taught. Despite this glaring deficit, Wohl offered characteristic grandstanding:

"I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."

Describing the operational workflow of IRIS C2, Wohl explained that vulnerability researchers frequently submit raw, incomplete research:

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

"Let’s say someone finds a flaw in a media decoder on a phone. A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do."

Wohl claimed that IRIS C2 employs approximately 40 individuals. However, he admitted that none of these purported employees are permitted to list their employment on professional networks like LinkedIn, citing "operational security" concerns—a convenient cover that mirrors the pseudonymous tactics previously deployed during their AI lobbying venture, LobbyMatic.


Future Outlook: Risks to the Cyber Ecosystem and Regulatory Blind Spots

The emergence of IRIS C2 highlights several systemic flaws in how the United States regulates federal contracting and monitors the proliferation of offensive cyber weapons.

  1. Vetting Deficiencies in Federal Procurement: The fact that Calvexa Group LLC successfully registered as a federal contractor despite its principals’ extensive criminal backgrounds—including felony fraud, civil rights violations, and record-breaking FCC penalties—points to critical gaps in government vendor screening processes. While the entity currently holds no direct federal awards, its mere registration grants an aura of institutional legitimacy that can be weaponized to lure unsuspecting young engineers and foreign talent.
  2. Exploitation of Junior Talent: By explicitly targeting junior engineers with high raw intelligence while dismissing the necessity of academic degrees, IRIS C2 creates profound professional and legal risks for impressionable developers. Researchers who hand over valid, highly dangerous software exploits to convicted fraudsters risk becoming unwitting accomplices in international cyber arms proliferation or unauthorized espionage activities.
  3. The Convergence of InfoOps and Cyber Arms: The trajectory of Wohl and Burkman demonstrates a dangerous evolution among fringe political operatives. Having exhausted the efficacy of domestic disinformation, robocalls, and fake intelligence firms, they have identified the high-margin, lightly regulated commercial spyware and vulnerability-brokering market as a lucrative frontier.

As federal agencies increasingly rely on private-sector vulnerability researchers to secure critical infrastructure, the presence of actors like Wohl and Burkman in the supply chain represents a severe liability. Unless defense oversight bodies and platform operators implement stricter identity verification and background checks for firms trading in offensive security capabilities, the illusion factory run by Wohl and Burkman will continue to exploit the gray zones of the global cyber economy.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *