I have a password the maximum length allowed so it's not trivial to unlock when she does that.
I suspect most of these reports come from either bugs in the software (and some quick Googling suggests this has been the case), or perhaps that even someone (heck, even a savvy child) was trying using some sort of brute force exploit to unlock the phone.
Ay my shop we didn't actually have a ton of success with graykey because most the devices were BFU. Once the agent is loaded, you can plug the phone into a regular charger and let it brute force itself into the next millenia. But after it tries te first few hundred passcodes, the rate drops significantly.
most people don't use "decent passwords" on their phones, because they have to enter it multiple times a day.