I'm conflicted about this. I know I'd be pretty upset if an employer starting talking to me about a plaintext password that's supposed to be hashed. The problem is that they
brute forced it and then sent it directly off to HR? Yes, as a sysadmin it's perfectly acceptable to be searching for weak passwords, but reading the plaintext yourself for fun then scurrying to HR is kinda a slimy thing to do. As an admin you have an obligation to your users to not be nosy, and if you find out something you shouldn't, keep it under your hat. Just because you have the ability to peek into the CFO's mailbox and see what everyone's salary is, doesn't mean you print out the spreadsheet and take it to your boss demanding a raise.
It's kinda like if you got in trouble for playing Farmville or whatever while sitting on the toilet at work, which they found out about by installing cameras in the stalls. Yes, I shouldn't have been doing that, but how you found out is also a huge issue and I'd feel pretty violated.
You should probably re-read the sudo warning:
We trust you have received the usual lecture from the local System Administrator. It usually boils down to these three things:
#1) Respect the privacy of others.
#2) Think before you type.
#3) With great power comes great responsibility.