These are the geek versions of "movie plot threats": increasingly unlikely contrivances of a combination of poor choices and brilliant evil genius which can only be addressed by the fact that the hero studied ballet back in high school which we know because he was razzed about it in scene two.
Back in real life: All four of your scenarios give me full access to the users table, right? That should be sufficient for me to run my favorite common passwords dictionary and compromise, hmm, 70% or so of them at my leisure. If I wanted a particular one, for example for the admin account or an email address which looked interesting, I could rainbow table it. If I wanted to be extra clever real name and email address gives me two extra datapoints to run for brute forcing and the opportunity for targeted spearphising, but hey, with successful compromise of most of several million accounts I'll already have my hands full stuffing my pockets with your users' money.
Like most proposed solutions added to stop movie plot threats, this one doesn't even work, but it does take mental bandwidth you could be using to implement security that actually matters. (Look how every always latches on to "you don't salt passwords!" and most ignore "Rails does not escape HTML by default, which puts every Rails site at the mercy of the worst coder remembering to h() all their tainted data.")