> That is, an employee violating an NDA for profit might be considered committing fraud against their employer.
I don't think so. Fraud would require an element of deception. Corporate espionage seems like a more probable avenue. IANAL, so I'm not sure who bears the liability here: the buyer, the seller, or both.
> What if Hindenberg offered $1M for access to a private list of donors to a [prominent abortion rights organization]?
This isn't equivalent. They're buying information, not selling it. Specifically, they're buying evidence of illegal acts.
Also, personally, I think there's a wide gap between the reasonable expectations of privacy for a business and an individual.
> But now that I think about it, why doesn't every successful private contract enforcement action end in a public prosecution for fraud?
There's usually not an intent to deceive, so it's not a crime. Also, the contract should specify the damages for violating it. The victim agreed to those penalties at the time of signing, so it wouldn't generally be in the interest of justice to add further penalties unless the behavior was so egregious as to override the victim's choice of penalty.
The accused can also often afford their own lawyers, which makes securing convictions a lot harder.
And there's a self-reinforcing penalty. If you have enough proof to get a conviction, you have enough proof to leak the leaker's name and make them unemployable.
And the criminal justice system is already stressed. These would likely end up getting plead down to something insignificant, because our justice system depends on most cases not going to trial.
There just isn't much to add from a criminal prosecution, and it would cost a lot.