Many companies try to avoid using encryption where the passwords are salted and hashed to something that is resource consuming like AES256 because it requires additional hardware, (servers, and other infrastructure). Since their main motivation is profit, they will often go with the bare minimum just to get the service working, unless the market demands something better/ more secure. Until the majority of computer users start working on gaining more understanding of encryption technologies and the concept behind increasing entropy in their passwords, many companies will be reluctant to invest in more secure systems (especially if any fines they get, ends up being cheaper than implementing better security).