Felons, Fraudsters Flog Offensive Cybersecurity Startup

A Dubious Cybersecurity Startup Emerges, Linked to Convicted Felons and Conspiracy Theorists

A cybersecurity startup claiming to offer lucrative payouts for zero-day security vulnerabilities has raised eyebrows due to its shady past. IRIS C2, operating out of McLean, Virginia, has been touting itself as a premier destination for vulnerability researchers and exploit developers, with the promise of million-dollar payouts. However, a closer look at the company’s leadership reveals a disturbing connection to convicted felons and far-right conspiracy theorists.

IRIS C2’s social media presence on X (formerly Twitter) boasts over 4,000 followers since its inception in January 2025. The account frequently posts about security vulnerabilities, AI, and software exploits, painting the company as a cutting-edge player in the cybersecurity space. However, the website linked to the profile, irisc2[.]com, reveals a more concerning narrative. IRIS C2 claims to be acquiring zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms, with payouts ranging from $10,000 to $7 million.

Digging deeper, it becomes apparent that IRIS C2 is linked to Calvexa Group LLC, a business registered in Virginia. The “contact” link on the website for Calvexa Group forwards visitors to irisc2[.]com, raising questions about the legitimacy of this setup. Government contracting portal g2exchange.com reports that Calvexa Group is operated by a business based in Virginia, but it does not appear to be working on any direct government contracts.

The owners behind IRIS C2 are Jack Burkman and Jacob Wohl, two individuals with a history of creating fake intelligence companies and using them to spread false claims about public figures. In 2019, Burkman and Wohl held press conferences falsely alleging extramarital affairs by Sen. Elizabeth Warren (D-Mass.) and then-2020 presidential candidate Kamala Harris. They were also prosecuted in multiple U.S. states for making thousands of robocalls to residents of battleground states and disseminating false claims about mail-in ballots.

In 2022, Wohl and Burkman both pleaded guilty to a single felony charge of telecommunications fraud in Ohio and sentenced to a fine, probation, and community service. The Federal Communications Commission (FCC) imposed a $5.1 million fine against Wohl and Burkman for their robocall campaigns in June 2023.

The emergence of IRIS C2 raises concerns about the potential misuse of cybersecurity expertise for malicious purposes. As the industry continues to grapple with the complexities of zero-day vulnerabilities, it’s essential to scrutinize companies like IRIS C2, which seem to be leveraging this expertise for questionable goals.

So what can you do to protect yourself? Be cautious when engaging with companies that promise unusually high payouts for vulnerability research or exploits. Verify the legitimacy of these companies by researching their owners and leadership. Remember, if a company seems too good (or lucrative) to be true, it probably is. Approach such opportunities with skepticism and prioritize your own security and well-being above any potential financial gain.


Source: Krebs on Security — 2026-07-08