The threat model is that this photo is shared with the Russian government and then the Russian government can match American citizens (or potentially people working in intelligence), and then using that in facial recognition programs. I.e. they can differentiate Americans (insert x country) from their own citizens and know who to watch more carefully.
This is a legitimate threat model. I'm not sure why you think it wouldn't be. Spies and others do use fake identities. The threat model is that there is that there is a way to determine who is faking their identities.