From that messed up email from support that leaked them. Or I assumed that you'll have a big cross-section with some other site that leaked.
This is not theory, this is hard-earned experience. Locking-out people is bad, the most that's acceptable is rate limiting to a once every few seconds.