I don't remember all the details, but one time at "a very large US Bank", a surveillance contractor saw "@largebank.com" email addresses in the public archives of an apache listserv and issued some type of takedown.
Apache responded by blocking all access from the bank's IPs including mirrors/other critical stuff...oops!