Identity:
identity, n.
4. "the state or fact of being the same one as described."
Those companies aren't trying to verify that information for its intrinsic suitability, and their goal isn't to facilitate a transaction with someone who merely has all of someone else's personal information- they're trying to make sure the person engaging in that transaction is the person indicated on the form. If they switched to say, a finger print, voice sample, DNA, and an in-person interview with an ID check, they would still be trying to validate your identity.
> stealing an identity isn't actually possible. What is possible is legally persuading a bank that you are someone else.
That's like saying murdering someone with a gun is incredibly difficult because unless you actually beat them to death with the gun itself, you're just aiming and pulling a trigger, which isn't even illegal in many cases.
Theft:
steal, v.
2. "to appropriate (ideas, credit, words, etc.) without right or acknowledgment,"
Appropriating your identity for the duration of a transaction certainly fits.
> Calling it identity theft when all someone has to do is get on to one of the many public data leaks and find your information is weird. It's not some kind of heist, it's using publicly available information to trick gullible banks.
Nothing in that definition requires the thing in question was suitably protected or appropriate for the job. Nothing requires that it be permanently stolen or that anything be removed from anyone's possession.
---
I agree that the data and mechanisms used are not up to the task, but only using arbitrary definitions of theft and identity and looking at the mechanisms of theft while ignoring the purpose of those mechanisms doesn't mean the term is wrong or that people aren't, by definition, stealing people's identities. You don't get to decide that people can't use specific, existing dictionary definitions to evaluate whether a term makes sense. And that's just from a technical perspective-- English is a descriptive language and terms mean what popular usage dictates they mean.
So unless you have some convincing arguments that nothing, by any definition, was stolen, that personal data wasn't being used to determine identity, and that the colloquial usage of the term doesn't actually matter, then identity theft is undeniably the correct term. The heistiness of the acts, other non-applicable definitions of the words, and the suitability of the methods of verifying identity are entirely irrelevant.