After a security breach , we can certainly change our PIN, password , or even some of the verification questions we have set. But we can't change our face. Imagine an attacker stealing a user 's biometrics and using them for illegal activities.

Biometric providers know that they are protecting very sensitive information, so they must be especially careful to prevent this from happening.
The US Department of Homeland Security recently came into conflict with biometric data providers, who are supposedly good at protecting data, perhaps better than most vendors in the space.
However, despite what they claim, we know that security can never be given or absolute.
And a security file that includes a user's face will also include a host of other sensitive information. There's no need to embellish this data to make it look convincing. That's one reason why medical records have become such a common target for hackers.
Facial recognition technology is certainly on the rise. China has been experimenting extensively with it, using machine learning, and many other countries have gotten into the game.

Singapore, for example, implements a national identity based on the face of its citizens.
Of course, with our constant exposure to social media, one could say that having our face out there isn't such a terrible thing.
However, if a user's biometric data, including their face, can be used to interact digitally with an ever‑growing number of businesses and organizations, it can essentially destroy their real life.
For example, someone could steal this information, use it for fraud or other malicious actions, and make it appear that these actions were carried out by the person from whom the information was stolen.
For the above reasons, the security of biometric data is particularly important and must be taken seriously by providers.
