An attacker rarely cracks a password. They just find the door nobody realized was a door at all.
Every online service you use - your bank, your mail, the shop you buy from - has one main entrance. There they ask who you are: email and password. That's the check. Its purpose is simple: to let exactly you in. Not the first passerby off the street.
The problem is a building rarely has just one door. There's a side one, for deliveries. There's a ground-floor window nobody thought to lock. If the main door has a sturdy lock but the side one has none at all, a thief doesn't bother with the main one. They just push the side door open and walk in.
Imagine logging into your bank account with a password, as always. But that same bank also has a separate page - say, for checking an exchange rate, or a support question - that asks for neither email nor password, because it looks harmless. If that page is connected behind the scenes to the same system, someone can walk straight through it to other people's data. They haven't guessed anyone's password. They've simply picked the door nobody realized was a door at all.
That's exactly why this phrase scares more than any other in a breach report. However complex a password you've come up with, it only guards the door it's put on. It doesn't guard the one next to it.
What sits underneath
As someone who builds such systems myself, this is what bothers me most. You pour weeks into the main entrance - strong password, extra verification, everything by the book. And then you leave some side feature open, because "it's internal, who's going to find it". They find it. Not people sitting around guessing passwords, but automated programs that walk around the building from outside, feeling every door and window.
So when I see the words "unauthenticated access" in a report like that, I don't look at how complex the company's password is. I look at whether anyone walked around the whole building at all, not just the front entrance.