For one of my older routers, for an ISP service I am not currently using - I signed up to dlinkddns.com with a dedicated email address. Basically this is a versioning service between the router (obsolete dyndns client) and dyndns.org. Today I caught phishing spam using the email. The inference is that the logon has been leaked somewhere in the chain.
I know there is a very slim chance it has been harvested during logon if sent "clearly" during that process. It has been a while since that would have happened last. Maybe it has even been purged as a dormant account. The address was used only twice by dyn, most recently in June 2010.
This is isolated enough to suggest it has not been ripped from any of my mailboxes.
Router was a DI-524, the private portion of the email was bender.dlinkddns
Just throwing it out there.