More

    Cybersecurity Startup Tainted by Convicted Felons and Fraudsters

    Cybersecurity Startup with a Controversial Legacy: IRIS C2

    In the realm of cybersecurity, the race for zero-day vulnerabilities is akin to the gold rush, with firms and hackers alike clamoring for newly discovered flaws in software that could be exploited for massive financial gain. Among them is IRIS C2, a startup making waves for its aggressive acquisition of these vulnerabilities in popular software. However, the story behind its founders is anything but conventional.

    Who’s Behind IRIS C2?

    At the helm of IRIS C2 are Jack Burkman and Jacob Wohl, two figures notorious for their far-right conspiracy theories and a series of legal troubles. Their previous ventures, which include staged intelligence companies and a now-defunct AI lobbying platform, have cast a long shadow over their current endeavor.

    IRIS C2, operating from McLean, Virginia, promotes itself as a firm specializing in offensive cybersecurity. Since its inception in January 2025, its Twitter account (@C2IRIS) has attracted over 4,000 followers, frequently discussing security vulnerabilities and exploits.

    The Business Model of IRIS C2

    The company claims to offer enticing financial rewards for research into security exploits, with payouts advertised as ranging from $10,000 to a staggering $7 million. The IRIS C2 website explicitly states its mission: “Attract the very best vulnerability researchers and exploit developers in the world.” This focuses primarily on junior engineers with high intellect, disregarding conventional qualifications like degrees or previous industry experience.

    Recent posts on their LinkedIn emphasize a deluge of applications, showcasing the startup’s aggressive hiring strategy. However, scrutiny reveals some unsettling details about its corporate structure.

    Unpacking the Corporate Identity

    Investigating the firm reveals that IRIS C2 is linked to Calvexa Group LLC, another Virginia-based company. Interestingly, the property tied to Calvexa Group is owned by Jack Burkman, a figure previously embroiled in various controversies, including disinformation campaigns. When approached for clarity, Burkman directed inquiries to Wohl, leaving numerous questions unanswered.

    A History of Controversy

    Jack Burkman and Jacob Wohl’s combined history is replete with scandals. The duo gained notoriety for making false claims about various political figures, including fabricated allegations against Robert Mueller and Pete Buttigieg. Following the 2020 elections, they faced criminal charges for attempting to suppress votes, culminating in significant fines and a civil settlement.

    Their legal troubles cast a shadow over IRIS C2. In addition to the criminal charges, they were hit with hefty fines from the Federal Communications Commission (FCC) due to their robocall schemes aimed at misleading voters.

    The Market for Zero-Day Vulnerabilities

    Selling zero-day vulnerabilities is a high-stakes game filled with a mixed bag of players, from seasoned researchers to outright fraudsters. Yet, the approach taken by IRIS C2 is notably bold and brazen. While many government contractors tread carefully around the optics of acquiring exploits, IRIS C2 shines a spotlight on its operations, attracting attention — both positive and negative.

    Their unabashed recruitment pitch aims to position the company as a hub for innovation in exploit discovery, despite the questionable backgrounds of its founders.

    A Question of Expertise

    Jacob Wohl has often claimed to have extensive technical knowledge, asserting, “I know more about tech than anyone.” However, he admitted to lacking formal education in cybersecurity, raising questions about the quality and validity of the exploits being developed under IRIS C2’s banner. He suggested that the firm’s role often involves refining preliminary findings into stable and reliable exploits — a process that carries its own risks.

    Employee Anonymity and Operational Secrecy

    Wohl further claimed that IRIS C2 employs around 40 individuals. Yet, he noted that none are permitted to disclose their affiliations on LinkedIn, stressing operational security. This raises concern about transparency and the ethical implications of working for a company with such a chaotic and controversial history.

    The AI Lobbying Venture

    In an interesting twist, Burkman and Wohl dabbled in tech-driven lobbying through a company named LobbyMatic. This venture claimed to utilize artificial intelligence to enhance political lobbying but was marred by deceit, with both founders operating under pseudonyms. Reports indicated that several employees resigned upon discovering their true identities, highlighting a troubling pattern of deception associated with their business practices.

    By delving into the dynamics of IRIS C2, one can see how the intersection of technology, politics, and ethics creates a complicated narrative, one that is still unfolding as the cybersecurity landscape continues to evolve. The allure of zero-day vulnerabilities brings both promise and peril, particularly when paired with the controversial backgrounds of their hunters.

    Latest articles

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    Popular