Yes, if site shares data with identity authority then a malicious identity authority can also share full identity data with the site.