Instead, give everyone a digital certificate with the private key stored in smartcards that don't allow anyone to copy the key, only to use it.
You could, of course, use real passwords, like every single service out there on the internet. Force some level of 2FA for security as well and you should be fine security wise.
Incremental plaintext numbers are not passwords, though. European countries have solved this problem in a variety of ways (that have been made cross-compatible and federated, even) and none of them use numbers on identification as a security number.
It can be done. Not everything must be electronic, and not everything must be centralized.
Only problem is you have to install a browser plugin that has to be compatible with your browser version and some non-technical people get confused. Apart from that it's actually a pretty good system.
It's now being replaced with a smartphone app, one that uses servers in the USA which poses all kinds of GDPR / privacy issues.
The smartphone app has significantly improved the user experience and can rely on biometric functionality, SMS and other verifications.
Overall, I think it's worth the risk if it's sufficiently defended cyber-security wise
And btw ID cards in the EU have chips with all the basic information on it as well, for use at airports and similar, and there are plans to use e.g. an app which reads from the chip to confirm possession of the card, and compare the photo on it with a selfie you take and confirm your identity digitally.
With any luck, the leak forces them to abandon it. But given people reporting on other comments that the leak was already denied, I'm not holding my breath.