Seems like it’s often the side channels that get people, even when they apply best practices to the primary system. I would be interested to know how passwords got into a log entry though.
If I have to guess, they maybe saved the plaintext from the form when testing the password reset feature for some reason?