Even that is often not enough: sessions are long lived and very often stealing a cookie is all the attacker needs.
If your security is breached every day passwords, whether you change them daily or not, are not going to save you.
It's not about one company being breached any more. It's about the entire world of password databases, rainbow tables, easy and fast cracking tools.
Why would that require changing passwords every day? You can’t use these tools without compromising the site first.
One of original motivations for password expiration was the belief that if your password DB was stolen, you had some significant amount of time before any malicious party would be able to crack a password and use it. That is no longer true: it's extremely likely that at least one user in your system has a password that is trivially cracked or in a rainbow table. Your system is vulnerable in a day, or less, after you've had your passwords stolen.
Rainbow tables are essentially instantaneous so one day isn’t enough either. If you care about that kind of scenario I’d say your energy is better spent on just picking a more suitable hash algorithm.
Absolutely. In the real world there's just no case for password expiration any more. Require at least 14 characters. Don't insist on any "complexity" rules, but do check passwords against a list of of common/stupid ones and reject them. Use a good hash algo, like bcrypt, scrypt, or Argon2