Convicted fraudsters are running a US startup offering $7 million for software exploits

IRIS C2 says it pays up to $7 million for zero-day exploits. Its owners are Jacob Wohl and Jack Burkman, best known for felony robocall convictions and a string of political dirty-tricks stunts.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: A shadowed office desk in a nondescript suburban business park at dusk
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • IRIS C2, a Virginia startup, publicly offers $10,000 to $7 million per exploit to buy unknown flaws in popular software.
  • The company is operated by Calvexa Group LLC, whose principals are Jacob Wohl, 28, and Jack Burkman, 60.
  • Wohl and Burkman pleaded guilty to telecommunications fraud in Ohio in 2022 and were fined $5.1 million by the FCC in June 2023 over voter-suppression robocalls.
  • Wohl told KrebsOnSecurity that IRIS C2 has around 40 staff and sells phone-hacking services to the US government, though he wouldn't name any contract.
  • In 2024, the pair were caught running a lobbying startup, LobbyMatic, under the fake names Jay Klein and Bill Sanders.

A US startup offering up to $7 million for hacking tools is run by two convicted felons with a long record of political hoaxes and fraud.

The company is IRIS C2. It says it's based in McLean, Virginia, and has built a following of more than 4,000 on X since January 2025. Its website offers to buy what the industry calls zero-days: previously unknown software flaws that let attackers break into devices before the maker can issue a fix. Payouts run from $10,000 to $7 million depending on the target. Governments and their contractors pay for these flaws all the time, but they don't normally advertise it this loudly.

Who actually runs IRIS C2?

Business records point to Calvexa Group LLC, a Virginia firm whose registered address is a property occupied by Jack Burkman, a 60-year-old lobbyist. Burkman passed questions from KrebsOnSecurity to his longtime associate Jacob Wohl, 28.

The pair aren't obscure figures. In 2019, they held press conferences accusing then-FBI director Robert Mueller of sexual assault. The claims were fabricated. They ran similar smears against Pete Buttigieg and Kamala Harris, and falsely alleged extramarital affairs by Senator Elizabeth Warren.

After the 2020 election, they were indicted in Cleveland on 15 felony counts over robocalls aimed at suppressing Black voters in Detroit. Both pleaded guilty in 2022 to a single felony count of telecommunications fraud in Ohio, receiving fines, probation and community service. A New York judge ruled in March 2023 that they'd violated federal and state civil rights laws; they settled for $1 million. Three months later, the FCC fined them $5.1 million, at the time the largest penalty it had ever sought under the Telephone Consumer Protection Act.

Wohl's record runs separately. Arizona regulators charged him with 14 counts of securities fraud in 2017. Two years later, he pleaded guilty in California to four felony counts of selling unregistered securities.

Should the public be worried?

Yes, but not in the way a ransomware story worries you. The concern is who ends up holding powerful hacking tools and how those tools reach government buyers.

Wohl told KrebsOnSecurity that IRIS C2 started as a penetration testing shop, meaning a firm hired to break into clients' systems to find weak spots, before shifting to selling phone-hacking services to the US government. He repeatedly mentioned federal contracts but wouldn't name any. Public contracting records show Calvexa is registered as a federal contractor but holds no direct government contracts.

"I know more about tech than anyone," Wohl told the outlet. He said he has no formal computer science training; what he knows is self-taught. He claims 40 employees, none of whom are permitted to list the job on LinkedIn. He also said, in May, that his own girlfriend didn't know what he did for a living.

There's precedent for the secrecy. Politico reported in September 2024 that Wohl and Burkman had been running a now-defunct AI lobbying startup called LobbyMatic under the aliases Jay Klein and Bill Sanders. Two employees resigned once they worked out who their bosses really were.

For security researchers approached by IRIS C2 or Calvexa Group at a conference, the practical point is simple: know who you're actually dealing with before you hand over your work. The louder a buyer shouts about its payouts, the harder it's worth looking at who's doing the shouting.

© 2026 Threat Vectr