They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
I deliberately throw away logs, customer data, etc once it ages last a certain amount simply so I can stop being responsible for it.
Combine that with a service that is compromised unknowingly for a long period of time and the attackers can siphon out a lot of IDs. Even a service which didn't retain IDs could leak a lot of data if the attackers tapped the verification server and exfiltrated all IDs as they passed through
Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
What does an "identity verification" company even do?
You'd think that 80 million people from a rich first world country would be enough of a market to use this.
No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.
So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.