This happens time and time again, enumeration, outright breaches etc - I've used aliases for as long as I can remember (2 decades maybe) and it's always the people you least expect - probably the most annoying one is where an azure specific alias was somehow enumerated and gets nonsense daily, mailgun also had an unacknowledged problem where you could enumerate domains during verification.
These days I'm moving to a completely randomized not human memorable model, because often the obvious aliases are also tried.
Incidentally I don't think I've ever had aliases shared they're typically just harvested as part of breaches or incompetence.