Headteacher had the most guessable username-password combo you could imagine

geekinchief1 pts1 comments

Headteacher had the most guessable username-password combo you could imagine

Jump to main content

Search

REG AD

Security

Headteacher had the most guessable username-password combo you could imagine

Schools often don't prioritize or understand cybersecurity

Avram Piltch

Avram<br>Piltch

US EDITOR

US editor

Published<br>thu 30 Jul 2026 // 08:00 UTC

PWNED Welcome, once again, to PWNED, the weekly column where we show you how not to use your computer or your network. In this week’s fable of fecklessness, we talk about a teacher who had a lot to learn about security.<br>Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request.<br>Our story comes courtesy of Kevin Walker, a seasoned IT veteran from the UK. At one point, he was providing his services to a school when he came across the headteacher’s (aka principal’s) laptop.

REG AD

At the bottom of the laptop there was a sticker with the woman’s username and password. Even if they had been complicated, the post-it would have given them away, but in fact, the combination was:

REG AD

Username: headteacher<br>Password: headteacher<br>Using that laptop, a malefactor could have had access to pupils’ personal information, internal conversations, emails, and all kinds of private school files. There could be serious problems for everyone who worked for or attended the school.<br>“A headteacher’s laptop is not just a laptop; it's an entry point to the most sensitive information a school holds,” Walker told us. If a cybercriminal got access, they could effectively break into the school without ever setting foot in the building.<br>This wasn’t the only instance of poor security Walker saw in his time doing IT for schools. He also saw an institution create an Excel file called Passwords.xlsx, then put it on a shared drive that students could get to. As its name suggests, Passwords.xlsx was filled with login credentials that any bad actor could take advantage of.<br>Walker also saw leaver accounts that remained active, a server that had its backup drive permanently plugged in so hackers could potentially wipe the backup as well, a Wi-Fi password written on a whiteboard in reception, and one critical system that users could only access from an ancient laptop.<br>There was also a machine with a “Do Not Turn Off” note posted to it sitting in a corner that everyone was afraid to touch. And, years after Windows XP was no longer the current platform, the school had a CCTV monitor with that ancient OS running on it. And, a supposedly secure server room doubled as a storage closet for stationery and Christmas decorations.<br>Walker told us that, in his experience, the schools he worked with had priorities other than cybersecurity and they didn’t understand its importance. One boss even denied the importance of keeping data safe at all.

MORE CONTEXT

Talking smack about a doctor got him access to private medical files

Law firm insisted on one password to rule them all

Thief posed as Wi-Fi fixing hero, then stole priceless trophy

Hackers shoveled snow for company, were rewarded with network admin access

“We don’t need to worry about cybersecurity. They're only a primary school,” his manager told him when Walker tried to get them to use cloud backups.

REG AD

The problem, Walker opines, is that schools often have to work with outdated gear and the teachers and school administrators have other concerns. His solution: keep it simple.<br>“Make the safe thing the easy thing,” Walker said. “Give staff password managers. Use multi-factor authentication. Review accounts properly. Test backups. Remove shared admin logins. Keep systems updated. Enforce proper passwords and block the ones that have already turned up in data breaches. If a password is already doing the rounds online, it has no business protecting a school system. None of that is as exciting as rolling out a fleet of shiny new iPads, but it works.” ®

pwned<br>security

REG AD

cyber-crime

Amazon links four poisoned npm packages to one North Korean crew

Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts

ON-PREM

Microsoft makes Copilot harder to miss in Classic Outlook

New button beside the ribbon promises consistency – and more questions for admins

The VMware deadline that could reshape your IT strategy

PARTNER CONTENT: With vSphere 8 support ending in 2027, IT leaders must navigate tight timelines and costs to modernize on their terms.

Legal

Hims & Hers accused of sharing health secrets and hiding the cancel button

FTC says Meta and Snap received sensitive patient information while customers faced unexpected prescription charges

columnists

Digital sovereignty is real in Europe. The UK? Not so much

Trump's unpredictability is pushing governments and businesses toward open source while Britain remains glued to US tech

DATABASES

MariaDB again faces questions over Galera's open...

password school walker headteacher laptop username

Related Articles