I would think they are guessing most people's passwords are weak or something. Like a screen pattern is weak, can be broken in just 300k attempts or maybe less because people use the same patterns and people can't be bothered to use passphrases.

PIN and patterns are secure because the security module enforces rate limits, you can't brute force effectively if every attempt after the first 10 takes a minute. Biometrics can be even better against brute force (more possible combinations) but they are vulnerable to cloning.

With a 6 digit code cracking it will take close to a year on average. With your screen pattern example it's around 100 days. That's more than enough time for the owner to notice and turn on anti theft features. Maybe even for the police to find and return the phone.

I think the average person doesn't know they can use the find my phone feature on Android to lock their phone. When their phone is stolen they just get sad and call it a day and get another one. Maybe report it to police if they care in their country if police don't care, they just get another phone the day after.

I would say pins are even less secure because people usually set it up as something like their birthday and thieves also often simultaneously steal some id card in a wallet which has exactly that.

A screen pattern is a different way to enter a PIN with no duplicate digits. Both PINs and patterns rely upon the security processor to resist bruteforces.