I think what they're saying is that someone could pretend to be a researcher and ask for passwords to confirm that they match what was found in some fictional breached data.
If I'm reading it right the part about them confirming that the records contained the password implies that they were given the relevant record and then they confirmed it was accurate, not that they were just asked "hey what is your password"
Defletter|9 months ago
OneMorePerson|9 months ago