99% of password theft currently comes from phishing. Most of the people that get fished don’t have a freaking clue they got fished oh look the Microsoft site link didn’t work.
Complex passwords that never change don’t mean s*** when your users are willing to put them into a website.