AFAIK there's a new law requiring KYC for IaaS providers serving the US. I'm assuming it covers their butts as well regarding malicious activity, they don't want to host a DoS attack, CP site, or similar. You might be hard pressed to find a hosting provider in the US that doesn't ask for these things.
* The rule would only apply to people living outside the US, so if you pay with a credit card with a billing address in the US from an IP in the US they probably wouldn't need to KYC you.
* KYC != "send me a photo of you holding your driver's license". I can open a bank account by just typing in my name, address, birthday, and SSN. That's enough KYC for a bank, it would be more than enough for a hosting provider even if that proposed rule became law.
What this company is asking for is beyond the pale even by full finance KYC standards. The most likely explanation is that an automated fraud detection system got set off and OP was selected for a much more rigorous review than they typically do.