They have and do. The issue is fraud and account compromises are so common (due to password reuse being the norm and every other site under the sun getting compromised), that they’re in a catch-22.
Support can be Social Engineered easily (especially if you don’t spend massive amounts of money on it). Making support not socially engineer-able is essentially impossible too with their user base, as the user base is too diverse.
Technical solutions currently suck, even if we ignore that most of the population is unable to effectively use them.
There is no consistent way across their user base to even verify a person exists, let alone that they are who they say they are, let alone that they are who created or owns the account!
And no one even puts the closest local equivalent into their Google account for legitimate reasons anyway.
Like who would want to upload their Birth certificate? Or passport? Or DL/ID? That’s a terrible idea. And many people don’t have the US equivalent to one anyway.
Not to mention, deep fakes have gotten really good. Not that a US company is going to have much luck identifying a fake (or real!) Belgian equivalent for instance anyway.
So they go with heuristics, which always have edge cases, try to hide what rules they use to avoid being gamed at scale, and hope for the best. Not great. But seriously, what else are they going to do?