Contact counsel or local police, as what you are reporting can be considered a civil or criminal matter in at least some jurisdictions; unauthorized access to electronic systems can be frowned upon, and counsel can certainly find these alleged shenanigans useful in some legal contexts.
Having the Wi-Fi password alone is insufficient to cause issues for other clients of the Wi-Fi network, so something else appears to be vulnerable and exploited in this network configuration.
Options for the network include setting up a kids’ network and segmenting the rest of the network devices off of that network and probably that VLAN or subnet or DMZ. Basically, a parallel Wi-Fi or guest network setup, but the kids are the guests here. This is feasible with mid-grade and higher networking gear.
Another option is to set up IEEE 802.1X / EAP / RADIUS and authenticate all clients accessing the network. This is more work and more complex (and more capable), and requires higher-end networking gear, so probably not a great solution here.
Another option is setting up MAC authentication, though MAC addresses can be spoofed. Some low-end and most mid- or higher-range Wi-Fi routers will support this.
If you have access to a Mac, the best (technical) way is probably by installing and using Apple Configurator app on a Mac to create a new (mandatory) profile with the Wi-Fi setup, and cabling to the iPhone or iPad and loading that profile. I don’t have a way to test this, but it should get access to the Wi-Fi network or guest network, without also providing the user with the Wi-Fi password. And what the user doesn’t have, they can’t share.
Some other details, two small, and one immense:
… Blocking Wi-Fi password sharing won’t block looking up the password and sharing that the old-fashioned way, too.
… Apple does not provide a way to block Wi-Fi password sharing, absent device management or device supervision, and that—past potentially creating and installing a Wi-Fi password profile—is probably more than you want to tangle with.
… Based on your posting, your entire network is seemingly massively breached too, and quite possibly persistently. A breached network is a fairly large project—hassle—to decontaminate and to reset and update and reconfigure everything, and to reload. Unauthorized hardware connected or unauthorized software installed on key systems, or deliberately-insecure configuration settings, can potentially be how this purported unauthorized network access is arising, as the reported issues are rather less likely to arise (solely) via Wi-Fi password disclosure.