If there are guardrails in place not to output sensitive data (good practice anyway), then how would this technique suddenly bypass that?
I still have trouble seeing a direct threat or attack scenario here. If it is privacy sensitive data they are after, a regex on their comparison index should suffice and yield much more, much faster.