Re-registering the domain would be easy and capturing/selling the credentials would be easy. Once you get an email running a "forgot password" on the "to" address across the top 500 domains might yield something fun. Also catching these specific type domains in drop would be easy with firstname/lastname scan. Cheap as well. Basically fraud based domain squatting.