When I was at Google there is a new hire class that talks a bit about security and 'bad' queries. There is an admonishment in the class notes to 'not' experiment with those queries unless you were a member of SecOps. They claimed they would notice, and they would track you down.
So to answer the meta question, all search engines have this problem. I know this is true because of the new hire class at Google (largest search engine) and because we (Blekko) offer our index through API access to a number of smaller brands you may have tried and by doing that we see what they see in terms of search queries.
Generally there is someone in an operations role at those partners with whom I can share notes and pass along the latest fashion in terms of scams.
By bad queries, you mean if you query "how to buy links without getting notice", Google will track you down, find out who you are, and try and get your sites penalized?
No, I mean queries that look for things like exposed credit card numbers or passwords, or vulnerable software. Web crawlers don't discriminate in what they index and inexperienced or inept web administrators sometimes put things out there that they shouldn't.
Criminals attempt to exploit that, using search engine results to figure out likely targets.
There are also people who try to exploit keyword searches and the advertisers who buy advertisements on them but that is less obviously criminal.
Interesting so Google has an "Internal Afairs" dept who audit themselves ie if some one looks up celbrities details internaly either for curiosity or to sell to the tabloid press.
I know that big telcos have internal security goups and British Telecoms had/has a ferocious rep.
BT got even stricter after some one got a temp job and looked up the x diretory numbers for one of the Queens residences.
After that they started doing posative vetting for team leads on major projects - that is the equivelent of TS clearance in the USA