Data breach report should search against all email addresses used in vault

According to this response, it appears to be using the HaveIBeenPwned (HIBP) API.

It would probably be worth editing the blog post to explicitly state this.