Are we positive the account was enabled? If what I think happened, happened, then they dumped Active Directory password hashes, in which case you don't see the account status by default when using popular tools. I sometimes do password analyses for corporations, and in the beginning, when I reported a few particularly weak passwords of particularly powerful accounts, they often told me that this was an account which had been disabled years ago, so this wasn't useful information to them. Eventually I started filtering out disabled accounts.

Then again, it sounds like this organization had many issues. (Why was the former employee's account still enabled? Why didn't they mandate MFA?)

Why would you think active directory has anything to do with this? That seems like a super random conclusion.

What happened is they found the password and email for an employee in a dump online - possibly for a different service, we don't know. If so, then the password was reused.

I mostly agree with you, but it's worth considering that there are much more fundamental issues with absolutely abysmal passwords like "123456" . If my password is "ra1nbowC0okies776", and it shows up in another place, it's a pretty strong signal that I reused it, because it's unlikely to have been picked independently by someone else. If my password is "password", even if I never reuse it, that's still far worse than me reusing the password above.

That is completely irrelevant to anything I said. No one on hacker news thinks that using 123456 as a password is a good idea.

You said the password was "reused". I think that's a poor framing and was pointing out.