EC-COUNCIL▊
The company that certifies the world's "ethical hackers" — with a documented, decade-long ledger of publishing other people's work as its own.
- ENTITY
- International Council of E-Commerce Consultants — owner of the Certified Ethical Hacker (CEH), CHFI, and ECSA programs FACT
- OPERATION
- Certification at industrial scale — by its own description, offered "in over 60 countries through a training network of more than 450 training partners" FACT
- EVENT
- Plagiarism documented in courseware, textbooks, and blog content, 2011–2022 ATTRIBUTED — plus the company's own blog takedown, 2021 FACT
- PATTERN
- Incident, apology, tool-blaming, repeat — attrition.org's assessment: "it keeps happening over and over" ATTRIBUTED
- DISPOSITION
- DEMAND MANDATED — CEH sits on the DoD 8570 approved-certification baseline; a slice of its market is regulation, not reputation FACT
Here is the gamekeeper of ethics — the animal that sells certificates of good conduct to hackers — observed for a decade by the field's most patient archivist, repeatedly carrying home other birds' nesting material and insisting the detection software approved it.
Official channel:
@ECCOUNCIL. From the company's published plagiarism-investigation statement (June 2021):
"…abundance of caution, we have pulled the entire EC-Council Blog site to allow a thorough investigation…" — and, on its process: posts passed
"plagiarism checks by industry accepted software." —
eccouncil.org/plagiarism-investigation/
A lineage note. This site is the professed successor to attrition.org's charlatan list, and this drawer is the one it inherits most directly: Jericho's crew kept the EC-Council file for over a decade, side-by-side comparisons and all. We summarize; the receipts below go to the originals.
Mind the register. Nothing here is a court finding. It is documentation plus admissions: researchers publishing comparisons, and a company publishing apologies. The question the file poses is narrow and fair — what does an organization that certifies professional ethics do when its own are tested? The timeline answers in the company's own words.
the drama timeline
ACT I — THE COURSEWARE (2011–2012)
The first entries in the ledger are not blog posts. They are the commercial product — the books and courses students paid thousands of dollars to study.
-
2011–2012
attrition.org opens the file
In quick succession, attrition.org documents plagiarism in the Alchemy blog (Nov 2011), the ECIH course (Dec 2011), the Ethical Hacking and Countermeasures and Disaster Recovery books (Dec 2011, both flagged "heavy plagiarism"), and Wireless Safety (2012). The archive also publishes its correspondence with the company, titled, with attrition's usual restraint: "Pleasantries, Lies, Bribe, and Threat."
ACT II — THE GATEKEEPER, BREACHED (2006–2016)
Interlude: while the plagiarism file grows, the certifier of hackers demonstrates its own perimeter, repeatedly, in public.
-
FEB 2014
Snowden's passport on the homepage
Eight years after a 2006 defacement, ec-council.org is defaced again. The attacker — alias "Eugene Belford," the villain from Hackers — posts Edward Snowden's CEH application email and passport photo on the homepage. Per The Verge, passports and government IDs of roughly 60,000 applicants, many US military and government IT professionals, were at risk. EC-Council was the victim of the crime; the file notes only what the incident showed about the certifier's own housekeeping.
-
MAR 2016
The site serves an exploit kit
The Register reports EC-Council's website serving the Angler exploit kit to visitors — the training ground for would-be white hats distributing, per the reporting, the era's premier crimeware delivery vehicle.
The field's immune response to all of this was not a lawsuit or a committee. It was a bookmark: attrition.org simply added each incident to the ledger, dated.
ACT III — THE BLOG (JUN 2021–MAR 2022)
A decade after Act I, the pattern reruns — except this time the copied party is a working security professional with her own audience, and the response is on the record within days.
-
JUN 2021
Alyssa Miller finds her own article
Miller discovers her article on the BISO role reworded and republished on EC-Council's blog and documents it publicly, noting that "instances of plagiarism by cyber security certification company EC-Council have been documented for over a decade." Within days, attrition.org documents Secureworks material on the same blog.
-
JUN 2021
The whole blog comes down
EC-Council pulls its entire blog site pending investigation and publishes a statement: the blog is "supported and maintained by many contributors including our members, volunteers, contractors, staff and SME's," and posts had passed "plagiarism checks by industry accepted software." attrition.org's published dissection of that statement: the company "does not take responsibility for what happened. Instead, they preemptively blame a wide range of people, the failure of tools…" — and, on the tools: "They have failed you repeatedly."
Note the recurring defense across the decade: the software approved it. An organization whose product is human judgment about ethics, outsourcing its own to a scanner.
-
MAR 2022
The blockchain book
attrition.org's ledger adds its most recent entry: plagiarism documented in EC-Council's Certified Blockchain Professional book. The file, at this point, spans eleven years.
ACT IV — THE MANDATE
Why does none of it move the market? Because a load-bearing slice of the market is not allowed to move.
-
ONGOING
DoD 8570 and the captive demand curve
CEH appears on the Department of Defense's approved 8570 baseline-certification list for cybersecurity workforce roles, carried forward into the DoD 8140 / DCWF era. For thousands of government and contractor positions, holding an approved certification is a condition of employment — demand set by regulation, insulated from the ledger above.
A certifier answerable to customers must mind its reputation. A certifier written into federal workforce policy must mind its paperwork. The incentives are not the same animal.
both sides, on the record
An eleven-year documented ledger — courseware, textbooks, blog, book again — kept by the field's most careful archivist, with side-by-side comparisons published for each entry [1].
The victims are the profession it certifies — working researchers and vendors whose material surfaced under the certifier's brand; Miller's account is first-party [3].
The pattern outlived every apology. The 2021 statement blamed contributor volume and failed tools; attrition's reply — "they have failed you repeatedly" — was demonstrated again by the 2022 book entry [2] [1].
It acted when caught. In 2021 EC-Council pulled its entire blog rather than triage quietly, published an investigation statement, and committed to editorial review — a costlier response than most vendors ever offer [4].
The certification program itself is externally audited. CEH is accredited by ANAB under ANSI/ISO/IEC 17024 — an independent standard for certification bodies. The plagiarism findings concern content production and marketing, not exam integrity, and no finding above says otherwise [7].
Nothing here is adjudicated. No court, regulator, or accreditor has ruled against EC-Council on any of it; the record is researcher documentation and the company's own statements. Its programs are recognized in over 60 countries and on the DoD baseline — gates that required review to pass [8]. And in the 2014 defacement, the company was the victim of a crime, full stop [5].
YOU DECIDE
Scoped to the claims. That the plagiarism was documented, repeatedly, across eleven years, is a matter of published side-by-side comparison. That the company apologized, blamed its tools, and was documented again is on the record in its own statements and the archive's. That none of this is a legal finding is stated plainly — and so is the reason the market never rendered one: part of the demand is written into federal workforce policy.
Weigh the costly signal: when its ethics were tested, the ethics certifier's repeated answer was that the software had approved it. The field's answer was to keep the file. You are reading the file.
The archive does not judge. It inherits the ledger and keeps it current.
evidence locker
THE PARENT ARCHIVE & FIRST-PARTY ACCOUNTS
PRESS & PUBLIC RECORD
The Verge — "Ethical hacking organization website defaced with Snowden's passport" (Feb 2014) ATTRIBUTED — the defacement and the ~60,000 applicants' exposure.
theverge.com/2014/2/24/5441386/…
EC-Council — Accreditations (ANAB / ANSI/ISO/IEC 17024) SELF-PUBLISHED — the defense's external-audit card, on its own site.
eccouncil.org/accreditations/
The standard. The plagiarism record is sourced to attrition.org's itemized, dated documentation, a first-party account by the copied author, and EC-Council's own published statements; it is stated as documentation and admission, never as a legal finding, because none exists. No individual is named as responsible and no motive is asserted. The company's remediation, its ANAB/ANSI 17024 accreditation, its scale, and its victim status in the 2014 breach are presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.