Hi Disease, Thanks for downloading SPA and this question!
Basically the password that they changed to has been previously seen on our breached database. Depending on what password policy you are applying, it can be every easy for someone to set a breached password. The MS default policy rules are pretty terrible, even with complexity switched on it still only means 3 out of the 5 different character types (upper, lower, digits, special and unicode), and mustn't contain your name (first, last, samaccountmane and displayname)
So things like Password1234 would be a perfectly acceptable 12 character, "complex" MS password, but of course we all know it isn't. and Password12345 would be fine when that one expired
Typically we see that if you are still running the MS rules you'll be doing really well if you have less than 25% of your users running a breached password - and remember the list you have downloaded is a small list.
Hope that explains it and if you'd like to know how to block these words in the first place, and moving to a better policy (other than just asking them to change it) then feel free to ask and i can take you through some options.
Cheers
Darren