If those are encrypted passwords, there’s another security failure. Three passwords are repeated, two of them repeated twice and one of them is repeated four times. That would mean that the users kept the default password that was assigned to them.
Default passwords are just too easy to guess what they are.
No, make that 4 passwords were repeated twice, and one four times.
There’s another way the press usually gets it wrong. Passwords aren’t encrypted, they’re hashed.