Because they don't need to know the PIN itself.
When you create a PIN, the system usually stores a transformed version of it (called a hash), not the actual PIN. When you enter your PIN, it transforms it again and compares the result.
If the results match, it's correct.
Any Cybersecurity Student Available??
Prove yourself...