A cybersecurity startup promising millions for exploits is linked to convicted felons with a history of spreading false information and engaging in voter suppression schemes. IRIS C2, which claims to be a company offering offensive cybersecurity capabilities, has gained over 4,000 followers on X/Twitter since its creation in January 2025. The startup’s website boasts about attracting top talent through high payouts for zero-day exploits, with prizes ranging from $10,000 to $7 million.
However, digging deeper reveals that IRIS C2 is linked to Calvexa Group LLC, a business registered in Virginia and operated by convicted felons Jack Burkman and Jacob Wohl. Both men have a history of creating fake intelligence companies and using them to spread false claims about public figures. They were also involved in voter suppression schemes through robocalls during the 2020 presidential election, for which they were sentenced to probation after their appeals to dismiss the charges were rejected.
Wohl’s LinkedIn profile highlights his experience as an investment firm founder at just 17 years old and his appearance on Fox News as “Wohl of Wall Street.” However, his past is marred by numerous scandals, including a $35,000 restitution order in Arizona for securities fraud and four felony counts of selling unregistered securities in California. In 2023, he was involved in a New York civil case where he agreed to pay a $1 million settlement after violating federal and state civil rights laws.
The IRIS C2 website claims to be hiring top vulnerability researchers and exploit developers, but the credentials of its owners raise significant concerns about the legitimacy of their business. With a history of spreading false information and engaging in voter suppression schemes, it’s unclear whether IRIS C2 is genuinely interested in acquiring zero-day exploits or if they are simply using this as a cover for more nefarious activities.
The fact that IRIS C2 is linked to Calvexa Group LLC, which has no apparent government contracts, raises questions about how the company plans to use the acquired exploits. With Burkman and Wohl at the helm, it’s possible that they could be using this platform to further their own interests or engage in malicious activities.
For cybersecurity professionals and enthusiasts, it’s essential to exercise caution when dealing with companies like IRIS C2. Before partnering with any organization, research their background thoroughly, and verify their legitimacy through government records and public databases. It’s also crucial to report suspicious activity to the relevant authorities, such as the Federal Bureau of Investigation (FBI) or the Federal Communications Commission (FCC), especially if you suspect that a company is engaging in voter suppression schemes or spreading false information. By being vigilant and sharing information with the cybersecurity community, we can prevent malicious activities and protect ourselves from potential threats.
Source: Krebs on Security — 2026-07-08