Bogus data releases, or ones that recycle data from old breaches, are common. Allison Nixon, a threat researcher with consultancy Deloitte, wrote a paper describing some non-intrusive techniques for figuring out if a data breach is legitimate. Nixon: “I would say that the motivations are really based on power, ego and fame” Other techniques include checking if a particular email address really was used to register an account with a Web service. In other cases, just looking at username and password combinations and the service that the details purportedly came from can send up a red flag.”]
Source: https://www.csoonline.com/article/2840901/how-to-figure-out-if-a-data-breach-is-a-hoax.html