1. there are programs which calculate and randomize numbers and letters until it finds the password
2. yes
You really think a hacker is going to go on each and every single account and do a randomizer until it works?
Like I said, they're gonna try the password listed there, and if it doesn't work, they'll move on to another account on the list.