Hackers use automated tools to crack passwords and can break a simple password in minutes. Social pressure or fraud can persuade users to divulge their passwords. The best security in the world is irrelevant if an attacker has a valid password.
Educate users to select strong passwords (avoiding obvious words and containing a mix of upper and lower cases, numerals and punctuation marks) and to treat their password as they would a PIN number. Change passwords regularly. If possible, use Windows Server password policies to enforce strong passwords.