← All news

vulnerability

UK student found the school admin password in plain sight

2026-06-25

Here is a story that should not be possible in 2026, and yet. A 17-year-old at a UK sixth form plugged his personal laptop into the school network, opened Active Directory, and found he could poke around domain controller tools and policy maps without authenticating. Inside the directory, in the description field attached to the domain administrator account, someone had thoughtfully written the password.

Three words. Horse fence ditch.

Backup admin accounts were no better. The Register, which spoke to the student under the name Nathan, reports the fallback credentials included gems like bd and bigbaddog. Once he understood what he was looking at, the access was almost comical in its scope.

What he could see

  • Every student and staff record
  • Remote Desktop into any server on the network
  • LanSchool, the classroom monitoring tool, including keystroke history
  • Firewall configuration and security policies
  • Staff and student mailboxes, because the school synced to Google Workspace with the same credentials

He could have reset passwords, deleted accounts, nudged a grade or two, or simply turned the lights off across the whole network. He did none of it. He kept the discovery to himself, finished school, and only told the story later. He also never reported the holes to the school, which means there is a reasonable chance the description field still reads horse fence ditch today.

How something this bad happens

Whoever set this up was not careless in one place, they were careless in several at once. Passwords do not belong in Active Directory description fields. They do not belong in cleartext anywhere a standard user can read them. A student's personal device should not be able to enumerate domain controller tooling on plug-in. And reusing the same admin password across the on-prem environment and Google Workspace means one slip exposes both worlds at the same time.

Any of these on its own would be a finding worth fixing. Stacked together, they describe a network that was held shut by nothing more than the hope that nobody curious would ever look.

The part nobody likes to say out loud

Strip away the technical detail and what is left is uncomfortable. The single factor standing between this school and a catastrophic week was the temperament of a teenager who decided the hassle was not worth the prize. He could have done anything. He chose to do nothing.

That is a lovely outcome and a lousy control. Security that depends on the goodwill of whoever wanders in first is not security, it is luck. Most schools, like most organisations, will not get this lucky twice. The lesson here is not really about Active Directory hygiene, although that is part of it. It is that the people inside your network, including the curious ones with no malice at all, will eventually see what is there to be seen. The only question is whether what they find is locked down, or written in the description field for them.

UK student found the school admin password in plain sight | RiskSense