They could have their passwords saved somewhere either on their device or the cheeky google “Save password for this website?” cookie. If I had a bit more context (maybe the section this question is coming from, the general topic you’ve been learning that included this question) I could even say they had remote access enabled, allowing someone to enter in their computer remotely to find these passwords.