Headteacher had the most guessable username-password combo you could imagine
Jump to main content
Search
REG AD
Security
Headteacher had the most guessable username-password combo you could imagine
Schools often don't prioritize or understand cybersecurity
Avram Piltch
Avram<br>Piltch
US EDITOR
US editor
Published<br>thu 30 Jul 2026 // 08:00 UTC
PWNED Welcome, once again, to PWNED, the weekly column where we show you how not to use your computer or your network. In this week’s fable of fecklessness, we talk about a teacher who had a lot to learn about security.<br>Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request.<br>Our story comes courtesy of Kevin Walker, a seasoned IT veteran from the UK. At one point, he was providing his services to a school when he came across the headteacher’s (aka principal’s) laptop.
REG AD
At the bottom of the laptop there was a sticker with the woman’s username and password. Even if they had been complicated, the post-it would have given them away, but in fact, the combination was:
REG AD
Username: headteacher<br>Password: headteacher<br>Using that laptop, a malefactor could have had access to pupils’ personal information, internal conversations, emails, and all kinds of private school files. There could be serious problems for everyone who worked for or attended the school.<br>“A headteacher’s laptop is not just a laptop; it's an entry point to the most sensitive information a school holds,” Walker told us. If a cybercriminal got access, they could effectively break into the school without ever setting foot in the building.<br>This wasn’t the only instance of poor security Walker saw in his time doing IT for schools. He also saw an institution create an Excel file called Passwords.xlsx, then put it on a shared drive that students could get to. As its name suggests, Passwords.xlsx was filled with login credentials that any bad actor could take advantage of.<br>Walker also saw leaver accounts that remained active, a server that had its backup drive permanently plugged in so hackers could potentially wipe the backup as well, a Wi-Fi password written on a whiteboard in reception, and one critical system that users could only access from an ancient laptop.<br>There was also a machine with a “Do Not Turn Off” note posted to it sitting in a corner that everyone was afraid to touch. And, years after Windows XP was no longer the current platform, the school had a CCTV monitor with that ancient OS running on it. And, a supposedly secure server room doubled as a storage closet for stationery and Christmas decorations.<br>Walker told us that, in his experience, the schools he worked with had priorities other than cybersecurity and they didn’t understand its importance. One boss even denied the importance of keeping data safe at all.
MORE CONTEXT
Talking smack about a doctor got him access to private medical files
Law firm insisted on one password to rule them all
Thief posed as Wi-Fi fixing hero, then stole priceless trophy
Hackers shoveled snow for company, were rewarded with network admin access
“We don’t need to worry about cybersecurity. They're only a primary school,” his manager told him when Walker tried to get them to use cloud backups.
REG AD
The problem, Walker opines, is that schools often have to work with outdated gear and the teachers and school administrators have other concerns. His solution: keep it simple.<br>“Make the safe thing the easy thing,” Walker said. “Give staff password managers. Use multi-factor authentication. Review accounts properly. Test backups. Remove shared admin logins. Keep systems updated. Enforce proper passwords and block the ones that have already turned up in data breaches. If a password is already doing the rounds online, it has no business protecting a school system. None of that is as exciting as rolling out a fleet of shiny new iPads, but it works.” ®
pwned<br>security
REG AD
cyber-crime
Amazon links four poisoned npm packages to one North Korean crew
Researchers say Sapphire Sleet socially engineered maintainers before publishing malicious updates through trusted accounts
ON-PREM
Microsoft makes Copilot harder to miss in Classic Outlook
New button beside the ribbon promises consistency – and more questions for admins
The VMware deadline that could reshape your IT strategy
PARTNER CONTENT: With vSphere 8 support ending in 2027, IT leaders must navigate tight timelines and costs to modernize on their terms.
Legal
Hims & Hers accused of sharing health secrets and hiding the cancel button
FTC says Meta and Snap received sensitive patient information while customers faced unexpected prescription charges
columnists
Digital sovereignty is real in Europe. The UK? Not so much
Trump's unpredictability is pushing governments and businesses toward open source while Britain remains glued to US tech
DATABASES
MariaDB again faces questions over Galera's open...