It's 2016 and idiots still use '123456' as their password

"MWR uses can perform over 20 billion guesses a second against Microsoft Windows password hashes"

Does this mean, that MWR had a datafile of password hashes and then tried their system against them.

As opposed to trying to logon to a real system, in which case shouldn't system speed of response actually slow down the rate of attack? Let alone protective account locking out stopping the attack after a few tries.

