Perhaps many, but I have over 500 accounts in my password manager, yet none of have been leaked per the password exposure report (which I assume is based on the https://haveibeenpwned.com/ database).
So perhaps the problem is overblown in practice, assuming you don’t use the same password in many sites.
And did mentioning these things just make the message disappear on US-based lemmy-instances?
I don’t believe it did.