I've been doing this for exact 20 years this week. I always use a unique address for each site (pretty easy; I just use a wildcard domain).
Pretty much everything has been leaked: most retailers, software companies, all phpBB forums, wordpress blogs, Experian, Amazon (3P Sellers, not AMZN itself), Dropbox, LinkedIn. The list goes on and on.
Notable exceptions: Google, Microsoft, Apple, IRS.
These days is a lot harder to see leaks, as most egregious spams get filtered even before it hits your server (I use GSuite).