Yes, it's a bit touchy... But you can already do it: Tools -> Messages -> Search (down the page).
Also you can set the message.eml template to receive notifications when a "bad" user send a private message. Just put in the hidden line of the template: "<%if msg_username eq '[bad user]'%>Bcc: email@example.com<%endif%>. But this is really more "touchy"!!