Well, this is scary.
I had [incorrectly] assumed to get a blue check, you had to have 2FA turned on.
Apparently, The president had neither a strong password or 2FA.
^^^ for what it's worth, this doesn't show up in the haveibeenpwned password database.