Could it be that the passwords were actually stored on the Active Directory side and then synced with Google?
I work in public ed.  We set the passwords in AD for the students and they sync up to Google.
We know what we have set in AD and we do not allow the students to change the password in Google.
We do allow students to change the password in AD and then it syncs with Google and we no longer know what their passwords are.
But, maybe in this previous location you did not allow self-serve AD password changes?
So it was just brought to my attention that the previous Sysadmin/Manager where I worked had a tool that would allow him to view the password(s) of a Google user. 
Does anyone know if that's related to GAM and outputting plaintext or a hash of the password? Or some other tool like a base64 decoder?
-- 
THIS TRANSMISSION IS INTENDED AND RESTRICTED FOR USE BY THE ABOVE 
ADDRESSEE ONLY.  IT MAY CONTAIN CONFIDENTIAL AND/OR PRIVILEGED 
INFORMATION EXEMPT FROM DISCLOSURE  UNDER FEDERAL OR STATE LAW. IN THE 
EVENT SOME OTHER PERSON OR ENTITY RECEIVES THIS  TRANSMISSION, SAID 
RECIPIENT IS HEREBY NOTIFIED THAT ANY DISSEMINATION, DISTRIBUTION,  OR 
DUPLICATION OF THIS TRANSMISSION OR ITS CONTENTS IS PROHIBITED. IF YOU 
SHOULD RECEIVE  THIS TRANSMISSION IN ERROR, PLEASE CALL US IMMEDIATELY 
AT 
618-684-3781, DELETE THE FILE FROM YOUR SYSTEM, AND DESTROY ANY HARD 
COPIES OF THIS TRANSMISSION. THANK YOU.
Murphysboro Community Unit School District #186
Murphysboro, Illinois