Is it possible for an Internet Service Provider to log keystrokes of its customers?

It would probably be unlikely that an ISP company would sanction such an action as a company policy, I imagine. But regardless, could a "bad guy" who works at an ISP implement such a technology (unknown to his ISP employer), then sell to other "bad guys" the log-in names, security questions, and passwords that he records?

Would appreciate any light shed on this subject.

Wanna B Ageek