Most people just don't get it. I like to get them to go to
';--have i been pwned? and just watch the realization come over their faces when they see how many breaches their common emails have been in.
Then I ask the million dollar question "do you use this password with more than one site?".
It's scary out there.
My personal MS account has constant login attempts from ip addresses all over the world. Most recent attempts (2 hours ago) were from Brazil and Los Angeles, I don't live in either place.
Figure it's because that email has been a part of several breaches.