Taking over a location from an MSP and I found that there were two accounts that were created in 2019 with only one login on that date in 2019, and the password was listed in the account description field..... Luckily this domain will only exist for about a week under our control before we move them to our domain.
Drafted an email for my management to review before I email the CEO of that MSP. Just to make sure it doesn't backfire on me. CYA since I am about to call out an MSP at horrible security.