Are we positive the account was enabled? If what I think happened, happened, then they dumped Active Directory password hashes, in which case you don't see the account status by default when using popular tools. I sometimes do password analyses for corporations, and in the beginning, when I reported a few particularly weak passwords of particularly powerful accounts, they often told me that this was an account which had been disabled years ago, so this wasn't useful information to them. Eventually I started filtering out disabled accounts.
Then again, it sounds like this organization had many issues. (Why was the former employee's account still enabled? Why didn't they mandate MFA?)
Why would you think active directory has anything to do with this? That seems like a super random conclusion.
What happened is they found the password and email for an employee in a dump online - possibly for a different service, we don't know. If so, then the password was reused.