How should they do this? They do not have your data. All they have is a collection of encrypted stuff.
You have to do it your self:
I was thinking that should check it the same way it does with exposed password, in that case it uses haveibeenpwned database, so I guess there is also a database with these kind of information as well. I think it can be really cool, don´t you think?
Feel free to ping if you want this feature request reopened.