I've caught a couple of hacked or sold email lists, but nothing that drastic yet.
One organization posted the email address I gave them on a public contact list webpage, so I get spam/phishing at that one.
Using a catch-all is the easiest way to do this, and I highly recommend it for other people.