I don't believe I've ever had passwords compromised. The only time I know I had malware was when I was a kid and installed a runescape autominer.. I've had some close calls with software vulnerabilities (I patched opensmtpd mere hours before bots started attacking it), but that's rare. haveibeenpwned only shows involvement in the last.fm compromise, which is a no biggie since I wasn't 1) using the service any more 2) using the same password with other services 3) using that email address with anything worth caring about.
By contrast, I've been burned by service providers blocking me many many times. They call this security but how is the equivalent of "we decided to take all your mail and not deliver it to you, and changed the locks to your apartment so nobody can get in" security? It's security in the same sense as "we decided to burn all your money so nobody can steal it, hope you're happy."
As a consequence, I've tried to cut out as many services and third parties out of my life as I can. It's an uphill fight though, and most services are hell bent on adding points of failure. E.g. where my bank before supported OTPs (in addition to login & password), now they require a phone too. It's probably not a matter of if but when I get bitten by this; I've had a Samsung Xcover physically break.
I think any notion of security should include secure access for the relevant party. If you can't access your stuff, security has failed (unless it can be demonstrated that there was an active attack going on and the only way to prevent it was to block everyone.. which these overzealous blocking systems in place can't demonstrate).