That instinct is correct, and it is the assumption the age assurance industry applies in its privacy-by design approach. No system can promise perfect security forever, so well-designed age checks do not depend on defending large stores of data. They depend on not creating them in the first place. A hacker cannot steal a database that was never built.
Data in transit is protected using strong encryption, and providers’ security management is audited against standards such as ISO 27001. Where any data must be retained temporarily to process the check, it should be encrypted at rest, access controlled, time limited and audited.
No one should claim invulnerability. The claim that can be made, and independently verified, is that the exposure is kept as close to zero as engineering allows, and that this is a categorically better position than the alternative, in which websites collect and keep dates of birth and ID copies themselves, while delivering the age-restrictions online which society has determined should be applied.