KYC is one way to prevent, not eliminate, hacking or theft cases. KYC is just one effort, not a guarantee without weaknesses. So, exploiting weaknesses might not be an issue with KYC itself, but rather could be a security system problem.
Now with the Advent of data leaks and agencies holding users data becoming a target for hackers, do you think KYC is still fulfilling that task of preventing scams?
What I can see is it aiding them to come to pass. Your leaked data gets to the black market, your security and privacy is already compromised and you're a direct target for scam, theft, impersonation or even blackmail. It's obvious KYC have failed, but the government would always give excuses and hold on to it because it's their greatest tool of control. Instead of reducing KYC requirements to the barest minimum for people's safety, they're expanding it's scope which puts people even in greater futuristic danger.