I used special emails for my kids’ savings accounts at a major brokerage, and then started getting weird emails to one of them. This was on a private domain and the addresses weren’t really guessable, so that’s how I knew they had been breached before they announced it weeks or months later.
Similar situation here. I've informed a handful of small site operators about their data breaches and been able to give them a lower bound for the breach date based on receiving spam.