Convicted Felons Are Behind a Flashy Zero-Day Startup Called IRIS C2

A cybersecurity company promising million-dollar payouts for zero-day exploits is run by two convicted felons with a long history of fraud and fabrication.

The company is IRIS C2, based in McLean, Virginia. Its X account @C2IRIS has picked up over 4,000 followers since January 2025, posting about vulnerabilities, AI, and exploits. The website offers $10,000 to $7 million for “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.”

Pretty straightforward pitch — except the people behind it are Jack Burkman and Jacob Wohl.

Burkman, 60, is a lobbyist. Wohl, 28, is his longtime associate. Together they’ve created fake intelligence companies, made fabricated sexual assault claims against public figures (including Robert Mueller and Pete Buttigieg), and ran a robocall scheme targeting Black voters in Detroit. They were sentenced to probation in late 2025 after appeals failed.

In 2022 they pleaded guilty to telecom fraud in Ohio. In 2023 a New York judge ruled they violated civil rights laws — they paid a $1 million settlement. The FCC hit them with a $5.1 million fine, the largest ever under the Telephone Consumer Protection Act at the time.

Wohl started investment firms at 17, earning the nickname “Wohl of Wall Street.” By 2017 Arizona charged him with 14 counts of securities fraud. In 2019 he pleaded guilty in California to selling unregistered securities.

So what’s IRIS C2 actually doing? Wohl told KrebsOnSecurity it started as a pen-testing company and shifted to selling phone-hacking services to the government. He claims 40 employees — none allowed to list their jobs on LinkedIn for “operational security” reasons. Wohl says he’s self-taught and has no formal computer science training.

“I know more about tech than anyone,” he said.

Government contractors buying zero-days usually keep things quiet. IRIS C2 is openly recruiting on LinkedIn. The company is registered as a federal contractor through Calvexa Group LLC but has no known government contracts.

One attendee at a cybersecurity conference last month told Krebs that Wohl and his team were approaching people to buy their vulnerability research. That’s how Krebs found out about the company.

The zero-day market has always had its share of charlatans and cybercriminals. But a company run by two people with this track record, publicly advertising for exploits, is something else entirely.