What I can't seem to wrap my head around is why if someone actually breached DB security that what they'd do with it is send spam . So, to me, that suggests that whatever breach might have occurred must have been minimal or via a non-critical system (i.e.: someone had an unencrypted copy of some set of users email addresses, possibly for marketing purposes, and their machine was compromised, etc.) Otherwise, it just…
Often, one of the best ways to hide that you've done something really bad is to let it slip that you've done something less bad, so investigators and other nosy people think they have solved the case.
This is also why, if you are using some scheme where you have an encrypted volume that is really two volumes, where one password reveals the volume that will get you sent to jail or executed, and one is the volume that is the decoy you give up after they think they have forced the password from you, you really should have something genuinely bad on the decoy. For instance have some porn that is legal but very taboo in your society, so that it makes sense for you to have protected it with strong encryption.