Since your lower bound ignores a common case: I use a formula based on the site to create a [unique]+[common] combined password, your premise that it is a lower bound is invalidated.
A better lower bound would be: find password hashes that occur with high frequency. "password1" and "wordpass" are probably each in the data a few thousand times (or rather their hash is in there a few thousand times).
Then use the logic that if a person is using an extremely common, known insecure password, that they're probably using the same lazy password in a lot of places. Use this as a lower bound, as it is a lot more defensible.