And how?
The Square Enix Account management system is completely different from the Square Enix MEMBERS site.
Now even if the Square Enix Account management system was hacked, off course token would be useless, but all the damn Square Enix services would be suspended anyway, so it's not like you would be even able to log on in the first place.
Customers are in a better stance if EVERYONE is "compromised", because SE would simply fix the hole, re-issue a password to everyone (or have them confirm their ID by contacting the Support Center or w/e), rollback characters data if character data were affected. And beside service suspension for couple of days (weeks at worse), there wouldn't be much damage to individuals.
Payment information, passwords, and such are (supposed) to be encrypted.
Biometry been used for a while, even for the average end-user. Fingerprint reader have been implemented on laptops, USB drives or available as external devices for over 10 years. And it never was expensive for the most basic ones ($40-50).My company actually has a finger print scanner lol, so they're made, I don't think they're for retail use yet though.