They are typically compiled from previous data breaches at various companies.
Use services like Have I Been Pwned to see if your email address has been leaked in a known public combolist. 247K MAIL ACCESS HQ COMBOLIST MIX .txt
Even if a hacker gets your password from a combolist, MFA stops them from accessing your account. They are typically compiled from previous data breaches