Felons Jack Burkman and Jacob Wohl Operate a $7 Million Zero‑Day Exploit Marketplace via IRIS C2
Investigative reporting reveals that self‑styled cybersecurity firm IRIS C2, backed by convicted fraudsters Jack Burkman and Jacob Wohl, markets zero‑day vulnerabilities to governments for up to $7 million, exposing a troubling overlap between criminal activity and the exploit‑sale industry.
Krebs on Security uncovered a $7 million price tag on a zero‑day exploit listed by IRIS C2, a Virginia‑based “offensive security” company that claims to sell vulnerabilities and full attack capabilities to government customers.
Who are the owners?
Jack Burkman, a 60‑year‑old professional lobbyist, and Jacob Wohl, a 28‑year‑old self‑styled “Wall Street prodigy,” have a long history of fabricating scandals, including false accusations against former FBI Director Robert Mueller, Indiana mayor Pete Buttigieg, and senators Elizabeth Warren and Kamala Harris. Between 2018 and 2020 they ran several sham intelligence outfits that spread disinformation during the 2020 U.S. election, leading to criminal convictions for fraud, false statements, and civil penalties.
IRIS C2’s business model
IRIS C2 markets “offensive security products” – essentially the acquisition of software vulnerabilities and their exploitation chains – with a public price list ranging from $10 000 for primitive primitives to a maximum of $7 000 000 for a cross‑platform full‑attack capability. The company’s recruitment tweet openly seeks “the brightest vulnerability researchers and exploit developers,” emphasizing talent over formal education.
The corporate entity behind the website irisc2.com is listed as Calvexa Group LLC, a Virginia‑registered company whose address is Burkman’s own residence in Arlington County.
Public statements and internal details
When Krebs contacted Burkman, he redirected the inquiry to Wohl, who told Krebs that Burkman does not handle day‑to‑day operations. Wohl claimed the firm originally performed penetration testing and only recently pivoted to “government phone‑listening services,” but offered no specifics. He boasted about his technical prowess and said the company employs about 40 staff who hide their roles on LinkedIn for “operational security.”
Wohl’s GitHub account is shown in the article, illustrating his online presence.
Past ventures
Before IRIS C2, Burkman and Wohl ran LobbyMatic, a company that purported to use AI‑assisted political lobbying. Under pseudonyms “Jay Klein” (Wohl) and “Bill Sanders” (Burkman), they attracted employees who later quit after discovering their true identities. Politico reported that large corporations purchased services from LobbyMatic.
Recent developments
In March 2024, journalist Molly White reported that Burkman and Wohl received a $300 000 deposit from a Canadian cryptocurrency fraudster seeking a presidential pardon, despite the fraudster not yet being convicted.
Conclusion
The article warns security professionals to avoid projects associated with Burkman or Wohl, noting that their extensive record of fraud makes their entry into the government‑focused exploit market especially concerning.
Source: Krebs on Security (https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/)
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
Black & White Path
We are the beacon of the cyber world, a stepping stone on the road to security.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
