I use a pattern of somecompany@mydomain.example for everyone I deal with.
Never made any effort to determine if they were leaks or sold, but here are the ones I've had to send to /dev/null over the years due to obvious spam.
adobe, godaddy, ebay, sirius, vonage, dzone, snapfish, walgreens, US postal service;they just continued their model of selling physical address data into the online space. Seems to have been sold to typical catalog vendors, JC penny, crate and barrel, etc.