Air France requires account password to be between 4 and 6 characters
twitter.com
twitter.com
I'm guessing they require this so you can type it in over the phone, that's the only sensible reason I can think of.
If you lock the specific account from all login attempts, you have a DoS opportunity on your hands.
If you lock the specific account from specific IPs, botnets win.
And I doubt a company would have requirements like this, and cross-ip and cross-account attack validations in place.