I used to create separate email addresses like the author. Then I realized it's a waste of time. Some will get used for spam - but what's the use of knowing the address came from site X? Either the site operator sold the addresses, the site got hacked, or they were otherwise compromised.
Either way you need a good spam filtering setup.
Incidentally, I don't see why the author thinks a PDF exploit was used. There are quite a few other exploits.