Not sure I understand — passwords are generally hashed in databases. Even if leaked, an attacker would still need to brute-force the hash to retrieve the actual password, wouldn’t they?
The https://haveibeenpwned.com/ project regularly shares new breached datasets. Reusing passwords across websites without MFA is just not not not recommended in 2025.