The account with the weak password was a former employee. It’s not on her/him that the account remained active and the admin password wasn't changed in the same process.