I would suspect a similar circumstance for the author's situation. Facebook does do some weird things to try to resume user engagement, but I've not really seen them re-active accounts on their own. More than likely it was password reuse resulting in a breach.
The Author even considered that the password was checked by some automation against sites like haveibeenpwned, which makes sense to me to some degree for Facebook to be actively checking against, but they seem to dismiss this in favor of a spying option.
I agree that having to submit a government issued ID seems a little incredulous for being able to deactivate the account, but as others have suggested, I'm not really sure how else the author can prove they are who they say they are. It seems that any such approach would be equally egregious to the public eye (i.e., anyone can make a fuss and shut down a facebook account), but certainly there must be some middleground, such as multiple authentications.
A lot of the sanity checks used by companies are pretty unreasonable for most users to remember or pass - Microsoft and Skype, for example, have basically locked me out of my main skype account; their recovery challenge was to name the exact account names of 6 of my contacts as well as the the last two group chats I had been a part of. Since I hadn't used the account in about 2 years, this was really difficult for me, and the account names were even more difficult since people were using handles instead of real names, so the exact formatting was all but forgotten.
Riot Games Inc. had similar methods, asking "what was the first skin you were gifted and who gifted it?" when my friend was trying to recover their hacked account. That was stuff that had occurred years ago, and we had no idea who gifted what and when.
Again, I don't really pretend to have a good solution for these scenarios, but such solutions seem like they're just obstacles for the actual owner instead of neerdowells that overtake accounts.