Three different sites have had breaches where I had accounts. One is old enough that it should be using an old password, other two should have unique passwords, and if not they're also using the same older password (I use neither of them anymore anyway, which is probably bad to have those accounts around regardless).
So long as a few specific services I use aren't compromised (all of which also include 2-factor authentication and a unique password) I'm not too concerned. Anything which contains sensitive information is behind a unique password and 2-factor auth.
What's really frustrating is I have an identity protection service (thanks for losing my person data, US gov't) through the OPM, and it set limits on how long (as in max length) my password could be and what characters my password could contain (as in, couldn't punctuation aside from period). What the **** is that about? Isn't that exactly counter-productive to what the service is designed to combat?
I had a blog. It sucked.