Ransom is the only thing I see happening to end user data.
Credential thefts facilitate theft of money. It might might help the attacker to rifle thru somebody's data to find information that helps answer "secret" questions, to trick friend and family into getting phished, and maybe blackmail, but I don't see a market for end user data that would drive data theft. Nobody is buying end user photos, videos, email, etc. (Anybody who would possibly buy it just tricks/entices users into giving it to them for free to train their AI models anyway.)
--
[0] - LLMs, whether multimodal or combined with modern AI-driven STT / TTS pipeline, enable running highly personalized scams cheaply and in an automated fashion, which does scale up and suddenly makes this data important. But that's a very new consideration, one which passkeys were not designed for, because it literally was not possible or conceivable even few years ago.
And yet, you don't. Which leads me to the conclusion that the data dump are overblown.
I think companies around the world come to the same obvious conclusion, which is why these data breaches keep happening, and the companies whose systems were breached are never any worse for the wear.