Krebs asking about plus addressing

I wonder if anyone here would have information on this question from the security blogger Brian Krebs?
Has anyone ever done research that looks at past breached databases to see what % in the data set included a "+" in the address followed by the name or shorthand for the breached entity? Seems like presence of even only a few 100 of these in a large data set is highly suggestive
