Simply not true. The "programmer community" IS a human institution, after all, and all the rules of sociology apply. In ANY human institution, the "good guys" outnumber the "bad guys" by a typically 10:1 margin. Problems occur when the "organization" re-defines the rules as to what constitutes a "good guy" (street gangs, the Mafia, etc.).
It's never been quantified and it never will be because it can't be. We do know this however...
http://www.securityfocus.com/news/7947