Example: I got a blackmail email. To prove they'd hacked me, they told me my password. Except I use a password manager and unique passwords, so I know exactly which website that password was from. It was a tiny e-commerce site that sold American candy that went bust. That breech isn't on HaveIbeenPwned. Needless to say, I ignored the blackmail.
Had exactly the same experience a few years back…. the data breach was Asda. I know because the disclosed password was based on a formula I use. Also ignored the email.