At the scale you'd expect that to happen, looking at credential dumps, you'd also expect to hear a lot about it.
And yet, you don't. Which leads me to the conclusion that the data dump are overblown.
I think companies around the world come to the same obvious conclusion, which is why these data breaches keep happening, and the companies whose systems were breached are never any worse for the wear.