Many users signup for each online service with a single-purpose email address. e.g. <servicename>@uniquedomain.com, so many customers will often know of a leak as soon as the service provider does.
As for single-purpose email addresses, that only works for cases where the service isn't selling account information, correct?
I don't know how you would tell the difference in that case so I assume yes.
The way I implement this is I bought an entire domain for spam. I created a catchall account and when I sign up for services I can just punch in hackernews@spam.com for example. All of this filters into a single email account allowing me to retrieve all my password resets and account confirmations.
This will weird out some people over the phone:
"Yes, it's comcast@spam.com"
"Sir, to look up your account I need YOUR email address"
Ah, but it does work (for me, twice). Of course spammers could strip the suffix. But since spam is a numbers game, I'm not sure it's worth the effort for them.