Jul 30, 2026
Policy

Headteacher password found on laptop sticker was also the username

UK IT veteran Kevin Walker says a headteacher laptop used the same obvious word for login and password, exposing school data risk.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Headteacher password found on laptop sticker was also the username
Photo: The Register

A headteacher password case shared by UK IT veteran Kevin Walker shows how basic credential failures can put school systems at risk: the laptop had a sticker on it showing both the username and password. Walker said the login was “headteacher” and the password was also “headteacher.”

Walker said he discovered the setup while providing IT services to a school. The school was not named, and Walker did not say that the laptop was breached. The issue was the exposure it created. According to Walker, a headteacher’s machine can serve as an access point to some of a school’s most sensitive information, including pupil data, internal messages, emails and private files.

The incident is mundane, which is why it is useful. Schools hold regulated personal information, but many still operate with stretched budgets, aging hardware and staff whose main job is teaching rather than security operations. In that setting, weak passwords and written credentials are not edge cases. They are predictable failure modes.

What happened with the headteacher password?

Walker said the headteacher’s laptop had a sticker on the bottom containing the credentials. The username and password were both the same obvious term: “headteacher.” If someone with bad intent had physical access to the laptop, Walker said they could have used it to get into school systems without entering the building by force.

The school’s specific systems were not described, and no financial damage, ransomware incident or data theft was reported. The risk, as Walker described it, was that the credential could have opened access to personal records and internal files that schools are expected to protect.

Other security problems Walker saw in schools

Walker said the headteacher laptop was not an isolated example from his work with schools. He also described a file named Passwords.xlsx being placed on a shared drive that students could access. As the name suggested, the spreadsheet contained login credentials.

He also cited former staff accounts that stayed active, a backup drive left plugged into a server, a Wi-Fi password written on a reception whiteboard and a critical system that could be accessed only from an old laptop. In another example, he said a computer with a “Do Not Turn Off” note sat in a corner because staff were afraid to touch it.

Walker also described outdated infrastructure, including a CCTV monitor running Windows XP years after that operating system was no longer current. He said one server room that was meant to be secure was also used to store stationery and Christmas decorations.

Why weak school passwords create more than an IT problem

Schools are attractive targets because they hold children’s personal information, staff records, emails and operational documents. A compromised administrator or headteacher account can give an attacker more than access to one inbox; it can become a route into systems that were not designed with hostile access in mind.

Walker said some school leaders he encountered did not treat cybersecurity as a priority. He recalled one manager dismissing his push for cloud backups by saying they did not need to worry because they were only a primary school.

His recommendations were basic controls rather than expensive security programs: give staff password managers, use multi-factor authentication, review accounts, test backups, remove shared administrator logins, keep systems updated and block passwords already found in breached data. The lesson for operators is direct: security that depends on busy staff making good manual choices tends to fail first.

This story draws on original reporting from The Register.

More from Policy

All Policy →