Would they even be able to do this? I was under the impression that keychain was e2e encrypted so you'd need the password and an existing device's passcode to unlock the password vault.
There are a lot of ways to address this, people just have to do it or face the inevitable consequences of not doing it.