EC-COUNCIL

The company that certifies the world's "ethical hackers" — with a documented, decade-long ledger of publishing other people's work as its own.

ENTITY
International Council of E-Commerce Consultants — owner of the Certified Ethical Hacker (CEH), CHFI, and ECSA programs FACT
OPERATION
Certification at industrial scale — by its own description, offered "in over 60 countries through a training network of more than 450 training partners" FACT
EVENT
Plagiarism documented in courseware, textbooks, and blog content, 2011–2022 ATTRIBUTED — plus the company's own blog takedown, 2021 FACT
PATTERN
Incident, apology, tool-blaming, repeat — attrition.org's assessment: "it keeps happening over and over" ATTRIBUTED
DISPOSITION
DEMAND MANDATED — CEH sits on the DoD 8570 approved-certification baseline; a slice of its market is regulation, not reputation FACT

Here is the gamekeeper of ethics — the animal that sells certificates of good conduct to hackers — observed for a decade by the field's most patient archivist, repeatedly carrying home other birds' nesting material and insisting the detection software approved it.

Official channel: @ECCOUNCIL. From the company's published plagiarism-investigation statement (June 2021): "…abundance of caution, we have pulled the entire EC-Council Blog site to allow a thorough investigation…" — and, on its process: posts passed "plagiarism checks by industry accepted software."eccouncil.org/plagiarism-investigation/

A lineage note. This site is the professed successor to attrition.org's charlatan list, and this drawer is the one it inherits most directly: Jericho's crew kept the EC-Council file for over a decade, side-by-side comparisons and all. We summarize; the receipts below go to the originals.

Mind the register. Nothing here is a court finding. It is documentation plus admissions: researchers publishing comparisons, and a company publishing apologies. The question the file poses is narrow and fair — what does an organization that certifies professional ethics do when its own are tested? The timeline answers in the company's own words.

the drama timeline

ACT I — THE COURSEWARE (2011–2012)

The first entries in the ledger are not blog posts. They are the commercial product — the books and courses students paid thousands of dollars to study.

  1. 2011–2012

    attrition.org opens the file

    In quick succession, attrition.org documents plagiarism in the Alchemy blog (Nov 2011), the ECIH course (Dec 2011), the Ethical Hacking and Countermeasures and Disaster Recovery books (Dec 2011, both flagged "heavy plagiarism"), and Wireless Safety (2012). The archive also publishes its correspondence with the company, titled, with attrition's usual restraint: "Pleasantries, Lies, Bribe, and Threat."

ACT II — THE GATEKEEPER, BREACHED (2006–2016)

Interlude: while the plagiarism file grows, the certifier of hackers demonstrates its own perimeter, repeatedly, in public.

  1. FEB 2014

    Snowden's passport on the homepage

    Eight years after a 2006 defacement, ec-council.org is defaced again. The attacker — alias "Eugene Belford," the villain from Hackers — posts Edward Snowden's CEH application email and passport photo on the homepage. Per The Verge, passports and government IDs of roughly 60,000 applicants, many US military and government IT professionals, were at risk. EC-Council was the victim of the crime; the file notes only what the incident showed about the certifier's own housekeeping.

  2. MAR 2016

    The site serves an exploit kit

    The Register reports EC-Council's website serving the Angler exploit kit to visitors — the training ground for would-be white hats distributing, per the reporting, the era's premier crimeware delivery vehicle.

    The field's immune response to all of this was not a lawsuit or a committee. It was a bookmark: attrition.org simply added each incident to the ledger, dated.

ACT III — THE BLOG (JUN 2021–MAR 2022)

A decade after Act I, the pattern reruns — except this time the copied party is a working security professional with her own audience, and the response is on the record within days.

  1. JUN 2021

    Alyssa Miller finds her own article

    Miller discovers her article on the BISO role reworded and republished on EC-Council's blog and documents it publicly, noting that "instances of plagiarism by cyber security certification company EC-Council have been documented for over a decade." Within days, attrition.org documents Secureworks material on the same blog.

  2. JUN 2021

    The whole blog comes down

    EC-Council pulls its entire blog site pending investigation and publishes a statement: the blog is "supported and maintained by many contributors including our members, volunteers, contractors, staff and SME's," and posts had passed "plagiarism checks by industry accepted software." attrition.org's published dissection of that statement: the company "does not take responsibility for what happened. Instead, they preemptively blame a wide range of people, the failure of tools…" — and, on the tools: "They have failed you repeatedly."

    Note the recurring defense across the decade: the software approved it. An organization whose product is human judgment about ethics, outsourcing its own to a scanner.

  3. MAR 2022

    The blockchain book

    attrition.org's ledger adds its most recent entry: plagiarism documented in EC-Council's Certified Blockchain Professional book. The file, at this point, spans eleven years.

ACT IV — THE MANDATE

Why does none of it move the market? Because a load-bearing slice of the market is not allowed to move.

  1. ONGOING

    DoD 8570 and the captive demand curve

    CEH appears on the Department of Defense's approved 8570 baseline-certification list for cybersecurity workforce roles, carried forward into the DoD 8140 / DCWF era. For thousands of government and contractor positions, holding an approved certification is a condition of employment — demand set by regulation, insulated from the ledger above.

    A certifier answerable to customers must mind its reputation. A certifier written into federal workforce policy must mind its paperwork. The incentives are not the same animal.

both sides, on the record

An eleven-year documented ledger — courseware, textbooks, blog, book again — kept by the field's most careful archivist, with side-by-side comparisons published for each entry [1].

The victims are the profession it certifies — working researchers and vendors whose material surfaced under the certifier's brand; Miller's account is first-party [3].

The pattern outlived every apology. The 2021 statement blamed contributor volume and failed tools; attrition's reply — "they have failed you repeatedly" — was demonstrated again by the 2022 book entry [2] [1].

It acted when caught. In 2021 EC-Council pulled its entire blog rather than triage quietly, published an investigation statement, and committed to editorial review — a costlier response than most vendors ever offer [4].

The certification program itself is externally audited. CEH is accredited by ANAB under ANSI/ISO/IEC 17024 — an independent standard for certification bodies. The plagiarism findings concern content production and marketing, not exam integrity, and no finding above says otherwise [7].

Nothing here is adjudicated. No court, regulator, or accreditor has ruled against EC-Council on any of it; the record is researcher documentation and the company's own statements. Its programs are recognized in over 60 countries and on the DoD baseline — gates that required review to pass [8]. And in the 2014 defacement, the company was the victim of a crime, full stop [5].

YOU DECIDE

Scoped to the claims. That the plagiarism was documented, repeatedly, across eleven years, is a matter of published side-by-side comparison. That the company apologized, blamed its tools, and was documented again is on the record in its own statements and the archive's. That none of this is a legal finding is stated plainly — and so is the reason the market never rendered one: part of the demand is written into federal workforce policy.

Weigh the costly signal: when its ethics were tested, the ethics certifier's repeated answer was that the software had approved it. The field's answer was to keep the file. You are reading the file.

The archive does not judge. It inherits the ledger and keeps it current.

evidence locker

THE PARENT ARCHIVE & FIRST-PARTY ACCOUNTS

  1. attrition.org — Errata: Charlatan — EC-Council (the full ledger, 2006–2022) ATTRIBUTED — the parent archive's dated, itemized documentation. attrition.org/errata/charlatan/ec-council/
  2. attrition.org — "EC-Council Deflects After Calls of Most Recent Plagiarism" (Jun 2021) ATTRIBUTED — the line-by-line dissection of the company's statement. attrition.org/errata/charlatan/ec-council/2021-eccouncil-response-to-plagiarism.html
  3. Alyssa Miller — "Plagiarism at EC-Council, an Open Response" (Jun 2021) ATTRIBUTED — the copied author's first-party account. alyssasec.com/2021/06/plagiarism-at-ec-council-an-open-response
  4. EC-Council — Plagiarism Investigation statement SELF-PUBLISHED — the takedown, the process defense, and the commitments, in the company's own words. eccouncil.org/plagiarism-investigation/

PRESS & PUBLIC RECORD

  1. The Verge — "Ethical hacking organization website defaced with Snowden's passport" (Feb 2014) ATTRIBUTED — the defacement and the ~60,000 applicants' exposure. theverge.com/2014/2/24/5441386/…
  2. The Register — "Security education outfit EC Council serving Angler exploit kit" (Mar 2016) ATTRIBUTED theregister.com/2016/03/24/ec_council_serving_exploit_kit_…
  3. EC-Council — Accreditations (ANAB / ANSI/ISO/IEC 17024) SELF-PUBLISHED — the defense's external-audit card, on its own site. eccouncil.org/accreditations/
  4. DoD Cyber Exchange — Approved 8570 Baseline Certifications FACT — CEH on the federal baseline; the mandate, primary-sourced. public.cyber.mil/wid/cwmp/dod-approved-8570-baseline-certifications/
The standard. The plagiarism record is sourced to attrition.org's itemized, dated documentation, a first-party account by the copied author, and EC-Council's own published statements; it is stated as documentation and admission, never as a legal finding, because none exists. No individual is named as responsible and no motive is asserted. The company's remediation, its ANAB/ANSI 17024 accreditation, its scale, and its victim status in the 2014 breach are presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.