some how i'm not all that surprised. it just fits the logic:
Well It's not like password strength matters that much anyway, we'd still need the db pw hashes to get in because you can only try 1 login every 90 seconds or something, would take years to brute it lol!
We had access to that account for weeks we just left it dormant.