Earlier quoted context omitted.
It always amazes me that in the US there is such a weak identification system, relying on a single number. Then it is apparently to the owner of said number to worry if it leaked.
The problem is that it's a username that is used as a password. In Europe you'd use some kind of tax identification number plus a physical copy of an ID card or driving license. My identification number is algorithmically derived from place and date of birth, first and last name and gender. Anybody who knows my address and has heard someone greeting me happy birthday can guess mine with two-three trials corresponding…
Nowadays things are better because computers are used everywhere We have a national ID system using 2FA which is pretty safe. Unfortunately, identify theft is still a thing.
Recently someone installed keyloggers on public computers. The second factor in the 2FA is a cardboard card with a list of one time password codes. You use a code on each sign in.
The criminals were able to determine when there were only a few codes left on the card. You then get a new cardboard card sent to your home address. They would stalk their victim's mail box and steal the new card as soon as it arrived.
With user name (your social security number) and password from the key logger together with the 2FA codes they were able to perform identity theft.
It's not easy to guard against attacks like this.