"Just seems that the wifi password should be known to whomever controls the router/wifi setup.: A remedial user of the network might be convinced to give out the password to someone who now has access to the network."
-------
Let the Network Administrator do their thing:
As for the network itself, this hacker would need the Administrator name and password. The Default Gateway would be used. If someone were to give it out, then change the password, then that would be a bit unsafe. So, change the password, if you think it has been hacked --everyone would have to change the password. And, if that's not bad enough, then get a new router. With a Static, rather than Dynamic, password, each user would be assigned their own user and password --you'd make each a standard user with their own password, and would do the same for the Administrator user.
Turn Off the SSID Broadcast:
While in the settings of the router, you might have the option to choose not to broadcast the SSID (the name of the network). Anyone getting in would have to know the SSID, or else they couldn't log in.