I remember some services send you a message telling you to change your password anytime a new device logs in or even fails to login to your account. That causes most people to pick weaker passwords, since they're not all using manager apps.
Why? Any breach that involves usernames/passwords are account name and password combos that get tried on EVERY POSSIBLE SITE after.
It only takes one pair of username with a reused password for this to work.
Use a password manager, and reset your password if the service has been compromised.
Expecting people to simply memorize a unique, strong password for every single website that they use is unrealistic. Of course, no solution is perfect, but that doesn't mean we shouldn't improve the current situation of people reusing passwords with maybe slight modifications per website.