I remember a few of these: "cust/custpw", "rcust/rcustpw", and "craft/craftpw" come to mind. Almost nobody removed or changed the password to these accounts.
We'd find the machines using a "wardialer" (named after the phone scanning scene in Wargames) app that would dial every number and look for modems. We used a DOS scanner called "ToneLoc." We lived in Cincinnati and could easily scan all kinds of local number prefixes for free that overlapped with areas that were likely to dredge up a rich PBX haul: downtown, near the airport, near universities, etc. A certain kind of weird 1200-bps answer with unusual parity settings (7E1 if I remember correctly) was a dead giveaway for one of these ridiculously vulnerable AT&T PBX machines.
Once you got in you could pull pranks, set up remote access lines to get "free" phone calls, set up party lines for you and your friends, etc.
I was like 14 or 15 at the time.
We also found other "phun" things with our wardialer including large outdoor signs with modems to allow remote configuration of the text they would display. If you saw "SMOKE POT EVERY DAY" and similar things a 15 year old would write on a highway or advertising sign in Cincinnati in the early 1990s that was us.
There was a real sense of exploration back then. When we scanned areas like downtown Cincinnati we'd find tons and tons of modems that would answer with mysterious (to us) prompts or blobs of binary spew that I'm sure represented protocols we didn't know how to emulate. A few times we managed to try obvious-sounding login/password pairs on some of these login prompts and find ourselves inside an Ultrix or a SunOS machine full of mysterious data. We really didn't bother anything on those machines, just looked around. We pulled pranks with things like signs but the only things we really ever messed with or possibly damaged were the PBXes. There were just too many fun things to do with those.
The weirdest thing I remember finding was something that initiated an Xmodem transfer and sent a black empty pixmap and then hung up. I wonder if it was some kind of camera or industrial monitor that was not actually working but was still on.
The most "alarming" thing we found was some kind of building controller that we assumed belonged to a downtown skyscraper and seemed to control elevators, which we didn't fuck with out of concern that it could actually hurt people. Don't know if you could have done anything dangerous with it but we didn't want to try so we just dropped that one.
There just wasn't a lot of security back then because it was all new and very few people knew how to do what we were doing. Even though Wargames popularized the idea of phone scanning people still seemed to assume that a live modem on a phone line was secure if the number was obscure.
All that started changing really rapidly in the late 1990s when tons of people got online.
Edit: found the scanner!