His password was "santabarbara"
About 19,600,000 results (on google search) for "santabarbara"
Maybe someone has Rainbow table and a bot setup so whenever a new account is created that exists in hackers database, the money is transferred automatically.
Oh, sorry, I thought
the question was his passphrase

Still, 12 symbols is not safe now? That's some serious brute-forcing...
Maybe some bitcoin miners repurposed their GPUs?

"santabarbara" is one word with 19 million google results. Someone has obviously pre computed the hashes of common passwords, so he is not brute forcing it on the spot. They already exist in attacker's database, The bot just checks if the account already exists in it's pre computed database.
If the password was sanTabarbara it might not have existed in attacker's database.