IC Technology & Cyber — 2026-07-10
Convicted Felons Behind Offensive Cyber Startup IRIS C2 Seek Zero-Day Exploits and Claim Government Contracts
BLUFAbsent any verifiable technical capability or contracting history, a formal U.S. government contract for Calvexa Group remains very unlikely within six months, leaving exploit-solicitation claims as unsubstantiated self-promotion.
KrebsOnSecurity reported that IRIS C2, a McLean, Virginia-based offensive cybersecurity startup soliciting zero-day exploits with payouts up to $7 million, is operated by Calvexa Group LLC, a Virginia entity registered at an Arlington address occupied by Jack Burkman 1. Burkman, founder of lobbying firm Burkman & Associates, referred questions to his longtime associate Jacob Wohl, who told Krebs in an interview that IRIS C2 shifted from penetration testing to phone-hacking services for the government and claims roughly 40 employees, though he cited no formal technical training 1. G2Exchange federal contracting records show Calvexa Group is registered as a federal contractor but has no listed direct government contracts 1. Both men were sentenced to probation in late 2025 on felony robocall-fraud charges tied to 2020 voter suppression schemes and previously ran the fake AI lobbying platform LobbyMatic under pseudonyms, details recounted by Krebs and republished by Latest in Cyber 12. Washingtonian separately noted the pair's history of public controversies in a broader roundup 3.
AnalysisConvicted felons with a documented history of fabricated fronts, including a fake AI lobbying platform, now solicit government-grade zero-day exploits without external accountability, a pattern that persists given Wohl's own admission of no formal technical background and reliance on unverifiable assertions about federal work. Federal contracting records show no direct government award to Calvexa Group as of this reporting, and it is
very unlikely a named, confirmed direct contract materializes within six months absent any documented pipeline beyond Wohl's claims. Moderate confidence reflects a single detailed primary account, from Krebs on Security, corroborated by public contracting records but no independent government source confirming or denying federal engagement. The aggressive self-promotion may function as a recruiting and credibility tactic rather than reflecting actual government engagement, leaving procurement security officers and vulnerability researchers vetting IRIS C2 exposed to an unaccountable broker whose legitimacy hinges entirely on a contract that has not materialized.
3 sources
- Felons, Fraudsters Flog Offensive Cybersecurity Startup - Krebs on Security
- Offensive Cybersecurity Firm IRIS C2 Linked To Convicted Fraudsters Jacob Wohl & Jack Burkman - Latest in Cyber
- Jacob Wohl and Jack Burkman Are Back, There's Trouble With Trump's Qatari Plane, and JD Vance Is Looking at Property in Virginia's Hunt Country - Washingtonian
View in full brief →