**The Controversial IRIS C2: A Closer Look at Cybersecurity, Disinformation, and Legal Troubles**
A cybersecurity startup, IRIS C2, has been making waves with its bold promise to pay millions for zero-day security vulnerabilities in popular software. However, beneath the surface of its seemingly professional operation lies a tangled web of far-right conspiracy theories, legal infractions, and questionable business practices.
IRIS C2 markets itself as a firm based in McLean, Virginia, offering offensive cybersecurity capabilities and paying substantial sums—ranging from $10,000 to $7 million—for vulnerabilities and exploits. Its recruitment pitch targets “junior engineers with raw talent” and emphasizes a lack of formal requirements, claiming to focus on skill and genius rather than traditional credentials. The company’s LinkedIn page boasts a high volume of applications, suggesting significant interest in its operations.
However, the firm’s leadership has drawn significant scrutiny. IRIS C2 is operated by Calvexa Group LLC, a Virginia-based federal contractor associated with Arlington attorney Jack Burkman. Burkman is a well-known figure with a history of controversial legal troubles. Alongside his associate, 28-year-old Jacob Wohl, Burkman has been involved in multiple high-profile disinformation campaigns. Their past includes fake intelligence companies like LobbyMatic, which falsely claimed to use AI for political lobbying, and a robocall scheme that led to felony convictions and a $5.1 million FCC fine.
Wohl’s background is equally troubling. Before his involvement with IRIS C2, he faced charges of securities fraud and selling unregistered securities. He also pleaded guilty to telecommunications fraud and was part of a scheme to suppress voter turnout through robocalls, for which he and Burkman were held in contempt of court.
The founder of IRIS C2, Jacob Wohl, has a self-described expertise in cybersecurity despite no formal training in the field. He has claimed to develop “spectacular” tech capabilities and asserted that his researchers frequently submit preliminary or incomplete findings, which his team polishes into reliable exploits.
Adding to the controversy, IRIS C2’s X/Twitter account has been flagged for spreading dubious claims. The stakes are high: while the market for zero-day vulnerabilities is populated by a mix of researchers, charlatans, and bad actors, IRIS C2’s brazen approach to selling exploits to the U.S. government stands out even in this shadowy industry.
KrebsOnSecurity initially learned of IRIS C2 when an attendee at a cybersecurity conference reported being approached by representatives of the firm. When contacted for comment, Burkman distanced himself from IRIS C2’s operations, leaving Wohl to defend the venture—a venture built on a foundation of legal penalties, dubious claims, and alleged disinformation campaigns.
—
**Source:** KrebsOnSecurity. “Cybersecurity Startup IRIS C2 Run by Far-Right Conspiracy Theorists, Convicted Felons.” June 2026. [https://krebsonsecurity.com/2026/06/irisc2-startup-zero-day-vulnerabilities/](https://krebsonsecurity.com/2026/06/irisc2-startup-zero-day-vulnerabilities/)



