"That seems to be a problem with the US SSN which is regularly part of the PII lost in data breaches."
The thing about US SSNs is that they're only required for certain government-related interactions (not even for tax, you can use a Taxpayer Identification Number instead)
Private companies were never supposed to process them and in most cases you don't have to give it.