8ish years ago, I wrote a script to search out Pis with port 22 opened to the internet with default un and pw. Let it run overnight.
The next morning I checked the log and it found thousands of Pis that I could have just logged into with root privileges if I wanted.
Never trust users.