Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names. The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities. The IRIS C2 website dangles the possibility of million-dollar payouts for exploits to attract talent. “Our business model is this,” reads a pinned post on top of the IRIS C2 account on X. “Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience.” The website linked in that profile — irisc2[.]com — says the company is hiring for a number of open positions, and a recent post on its LinkedIn page enthuses about an overwhelming number of applications from potential employees. The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value.” The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based in Virginia called Calvexa Group LLC . The “contact” link on the website for Calvexa Group — calvexagroup[.]com — forwards visitors to irisc2[.]com. G2Exchange shows that while Calvexa Group LLC is registered as a federal contractor, it does not appear to be working on any direct government contracts. A search on the Arlington, Va. address listed in the incorporation records for Calvexa Group LLC finds the property is occupied by Jack Burkman , the 60-year-old founder and managing partner of the lobbying firm Burkman & Associates . When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl . Jack Burkman (left) and Jacob Wohl, at a press conference in August 2020. Image: Wikipedia. Burkman and Wohl have a storied history of creating fake intelligence companies and using them to spread false claims about and frame public figures, including fabricated sexual assault claims against then FBI director Robert Mueller , and Pete Buttigieg , then mayor of South Bend, Indiana and a Democratic candidate for the presidency. In 2019, Burkman and Wohl held press conferences falsely alleging extramarital affairs by Sen. Elizabeth Warren (D-Mass.) and then-2020 presidential candidate Kamala Harris . In the wake of the 2020 presidential election, Wohl and Burkman were prosecuted by multiple U.S. states for making thousands of robocalls to residents of battleground states and disseminating false claims about mail-in ballots. They were indicted in Cleveland on 15 felony counts of orchestrating a robocall scheme aimed at suppressing the black vote in Detroit, and were sentenced in late 2025 to probation after their appeals to dismiss the charges were rejected. In 2022, Wohl and Burkman both pleaded guilty to a single felony charge of telecommunications fraud in Ohio, and sentenced to a fine, probation, and community service. In March 2023, a judge in a New York civil case ruled that Wohl and Burkman had violated federal and state civil rights laws, and the two agreed to pay a $1 million settlement. In June 2023, the Federal Communications Commission (FCC) imposed a $5.1 million fine against Wohl and Burkman for their robocall campaigns, at the time the largest fine ever sought by the FCC under the Telephone Consumer Protection Act. Jacob “Jay” Wo…
AI Analysis
Technical Summary
IRIS C2 is a cybersecurity startup that advertises the acquisition and sale of zero-day vulnerabilities, promising high payouts to researchers and exploit developers. It is operated by Jack Burkman and Jacob Wohl, individuals with a documented history of criminal and fraudulent activities, including fake intelligence operations and robocall fraud. The company is registered as Calvexa Group LLC, a federal contractor with no active government contracts. The startup's public presence includes social media and websites promoting offensive cybersecurity capabilities and recruiting talent. There is no technical evidence or confirmed exploits linked to IRIS C2, and no active threats or vulnerabilities have been reported. This report highlights concerns about the legitimacy and ethics of the company rather than a specific security vulnerability.
Potential Impact
No direct technical impact or exploitation has been reported. The primary concern is reputational and ethical, as the company is run by individuals with a history of fraud and conspiracy, which may affect trust in any vulnerabilities or exploits they claim to possess or distribute. There is no indication that any zero-day vulnerabilities acquired or sold by IRIS C2 have been used maliciously or have caused harm.
Mitigation Recommendations
No technical mitigation is applicable as there is no confirmed vulnerability or exploit associated with this entity. Security professionals should exercise caution and verify the legitimacy of any vulnerability disclosures or exploit offers from IRIS C2 or related parties. Due diligence is recommended before engaging with or trusting information from this source.
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Description
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names. The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities. The IRIS C2 website dangles the possibility of million-dollar payouts for exploits to attract talent. “Our business model is this,” reads a pinned post on top of the IRIS C2 account on X. “Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience.” The website linked in that profile — irisc2[.]com — says the company is hiring for a number of open positions, and a recent post on its LinkedIn page enthuses about an overwhelming number of applications from potential employees. The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value.” The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based in Virginia called Calvexa Group LLC . The “contact” link on the website for Calvexa Group — calvexagroup[.]com — forwards visitors to irisc2[.]com. G2Exchange shows that while Calvexa Group LLC is registered as a federal contractor, it does not appear to be working on any direct government contracts. A search on the Arlington, Va. address listed in the incorporation records for Calvexa Group LLC finds the property is occupied by Jack Burkman , the 60-year-old founder and managing partner of the lobbying firm Burkman & Associates . When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl . Jack Burkman (left) and Jacob Wohl, at a press conference in August 2020. Image: Wikipedia. Burkman and Wohl have a storied history of creating fake intelligence companies and using them to spread false claims about and frame public figures, including fabricated sexual assault claims against then FBI director Robert Mueller , and Pete Buttigieg , then mayor of South Bend, Indiana and a Democratic candidate for the presidency. In 2019, Burkman and Wohl held press conferences falsely alleging extramarital affairs by Sen. Elizabeth Warren (D-Mass.) and then-2020 presidential candidate Kamala Harris . In the wake of the 2020 presidential election, Wohl and Burkman were prosecuted by multiple U.S. states for making thousands of robocalls to residents of battleground states and disseminating false claims about mail-in ballots. They were indicted in Cleveland on 15 felony counts of orchestrating a robocall scheme aimed at suppressing the black vote in Detroit, and were sentenced in late 2025 to probation after their appeals to dismiss the charges were rejected. In 2022, Wohl and Burkman both pleaded guilty to a single felony charge of telecommunications fraud in Ohio, and sentenced to a fine, probation, and community service. In March 2023, a judge in a New York civil case ruled that Wohl and Burkman had violated federal and state civil rights laws, and the two agreed to pay a $1 million settlement. In June 2023, the Federal Communications Commission (FCC) imposed a $5.1 million fine against Wohl and Burkman for their robocall campaigns, at the time the largest fine ever sought by the FCC under the Telephone Consumer Protection Act. Jacob “Jay” Wo…
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
IRIS C2 is a cybersecurity startup that advertises the acquisition and sale of zero-day vulnerabilities, promising high payouts to researchers and exploit developers. It is operated by Jack Burkman and Jacob Wohl, individuals with a documented history of criminal and fraudulent activities, including fake intelligence operations and robocall fraud. The company is registered as Calvexa Group LLC, a federal contractor with no active government contracts. The startup's public presence includes social media and websites promoting offensive cybersecurity capabilities and recruiting talent. There is no technical evidence or confirmed exploits linked to IRIS C2, and no active threats or vulnerabilities have been reported. This report highlights concerns about the legitimacy and ethics of the company rather than a specific security vulnerability.
Potential Impact
No direct technical impact or exploitation has been reported. The primary concern is reputational and ethical, as the company is run by individuals with a history of fraud and conspiracy, which may affect trust in any vulnerabilities or exploits they claim to possess or distribute. There is no indication that any zero-day vulnerabilities acquired or sold by IRIS C2 have been used maliciously or have caused harm.
Defensive Guidance
No technical mitigation is applicable as there is no confirmed vulnerability or exploit associated with this entity. Security professionals should exercise caution and verify the legitimacy of any vulnerability disclosures or exploit offers from IRIS C2 or related parties. Due diligence is recommended before engaging with or trusting information from this source.
Technical Details
- Article Source
- {"url":"https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/","fetched":true,"fetchedAt":"2026-07-08T15:18:37.835Z","wordCount":1585}
- Classification
- {"confidence":0.55,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6a4e6a4ec9d9e3dbe3544382
Added to database: 07/08/2026, 15:18:38 UTC
Last enriched: 08/07/2026, 05:43:39 UTC
Last updated: 08/22/2026, 16:02:10 UTC
Views: 247
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.