What should one try to do to protect against this?
Hypothetical actions to take:
Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail.
Take particular care to have a "recovery" email address that is used for nothing else. Don't forward it to your regular mail, naturally.
Enable two-factor auth for email if you possibly can.
Have a credit card that is only used for online stuff.
Can one get a second address that is used only as a billing address? How would one do that? (A P.O. box? Expensive! A friend's house? I fear that credit card companies will leak this address like a sieve no matter what I do.)
EDIT: Startup wizards, here's a Minimum Viable Product: a credit card that can only be used for online accounts - which you must whitelist as you add them, via two-factor auth with your phone - and that features two billing addresses: The real one where the bills go and a dummy one that still validates. (Is that even legal under the CC rules? Sigh.)
The other suggestions in the article: Disable Find my Mac, reduce coupling between your accounts… was there something else?
Alas, nobody who isn't crazy paranoid is going to bother jumping through all these hoops. (I have tried to fight that paranoia but I think I'm losing that battle.)