Two-factor authentication would mitigate that, to some extent.
Tell you what... Two-factor authentication that requires a phone number and there will be a whole bunch leave here including myself.
This is a direct form of real personal physical identification including full name and physical address. Very few with any knowledge of how it actually works will use a site with 2FA. You don’t want your phone number in ANY database... Anyone who does is foolish and just asking for even more security risks.
And no... There is no system on the planet that is secure and can claim that this data will never be breached. This site is now in the Cloud and on servers in the old world who demands that data is turned over whenever requested. While the FR domain might not, their host just might and probably without notice.