The most basic cybersecurity rule is to keep personal information out of passwords. Yet within the District, two initials and a birthday are all it takes to access the sensitive information inside a student’s account.
Every student knows the password formula, and some log in to friends’ accounts as a prank. “I feel like [hacking into each other’s accounts] was just always known to me throughout my time at Menlo-Atherton. For jokes, we used to log in to friends’ accounts. It’s never been difficult,” JT Roeder ’26 said.
In August, the hacking turned malicious. In the span of weeks, hackers leaked random students’ personal information, used racial slurs, circulated threats on their behalf to teachers and peers, and deleted students’ work, forcing them to waste days recovering accounts.
The District’s solution, an email simply asking students to change their own passwords, is shoddy at best. Most students want to keep the passwords that they are familiar with, and an email isn’t enough to convince them—especially when they don’t think their school accounts have anything worth stealing.
Senior Sophie Marks didn’t change her password because she didn’t think that it was necessary. “I knew it was an option, but no one did it at the beginning of the year, and I didn’t think there was a huge need to. Because why are people going to use my school account? What [would] they want from my school [account]?” she said.
Marks woke up to a flood of notifications about hateful emails that she didn’t send. “I checked my recently sent, and it’s just a bunch of mean words to all my teachers,” she said. “I was shocked. Like my heart dropped.”
She quickly changed her password, but it was too late to prevent further damage. The hacker deleted all files in her Google Drive.
“I didn’t think [the hacking] was going to be an issue ever, but now that it is, I’m really worried about all the other stuff that could potentially be happening,” Marks said.
Similarly, hackers deleted senior Claire Gracia’s entire drive, which included college essays. “It’s so stressful when you don’t have control over all of your college essays and everything,” Gracia said. Restoring her account took several days and trips to the office.
Damages sometimes went beyond just files. “[A friend] reached out to me about losing money because of the hacking,” an anonymous student said.

When some students tried to change their passwords to prevent these losses, technical difficulties discouraged them, convincing them that changing it wasn’t worth the struggle.
Senior Esmé Allan tried to change her password after hearing that her friends had been hacked, but ran into issues. “I went to the page where it said to change your password, and it wouldn’t let me,” she said. When she clicked the “Change Password” button, an error appeared and wouldn’t let her proceed.
Many missed M-A’s response to the hacking or didn’t take it seriously. This is the second time in a year that the District hasn’t taken significant action to prevent security breaches. Last fall, phishing emails sent from hacked staff accounts cost some students thousands of dollars.
“When people started getting hacked, the school should’ve reset everyone’s passwords, not just wait until [the hacking] happened,” senior Claire Gracia said.
It’s time to take online student security seriously. The District must give students randomized passwords when it issues their accounts. Formulaic passwords make freshmen’s lives easier for one week, but leave students vulnerable to hackers for the next 4 years. Students who have already been hacked also need a clear and published protocol from the District for recovering their files, rather than days of stress and confusion at the office.
Teachers can currently change students’ passwords, and a simple method to look up a student’s randomized password if they forget is both possible and advisable. For returning students, the District must reset every password itself to prevent further attacks.
None of this is complicated or unheard of. The nearby Menlo Park City School District issues randomized passwords to its students. “[In middle school], the passwords were random, and you just had to memorize yours,” Roeder said.
If this system works for 10-year-olds in elementary school, it can work for high schoolers too. Surely schools in the heart of the world’s tech hub are capable of having a functional password and online security system.
To reset your password, visit this link.
Lilia Wilkiewicz, Louisa King, and Vesta Kassayan were the lead authors of this article.



