I don't know much about this particular implementation. However, with my rudimentary understanding of the funcionality, the RFID unit will have a ticket number reference on it, or perhaps (the way I would implement it) an indirect index to a ticket number reference. So the ability to read your RFID will get you a number that has no Personally Identifiable Information value.
As far as cloning it, someone with the ability to make a clone of your RFID could gain park entrance, and, if you've enabled it, enter your room, charge to your room account, use your dining credits, etc. But *not* to steal your identity (in a more general way outside of the resort context - such as bank accounts or get credit in your name, etc.) because the PII necessary to do that will not be on the RFID. He would have to have separate intelligence to enter your room (such as watching to see what room you access) since cloning would not reveal your room number. Also, it would not reveal your PIN, so anything requiring your PIN (such as dining plan, etc.) will not be accessible, unless he stole your PIN separately (by observing you entering it, for example). Also, once you use it the first time for park entry, the system will record your biometric information, so anything requiring that would not be possible.
Other illegal activities (I can't think of any, but there might be) would be quickly detected because there would be conflicting activities taking place at multiple locations, or other easily observable anomolies.
But encryption would make cloning very difficult and even if you can defeat that, cloning really doesn't give you much benefit (for the reasons described above) and so I'm not sure what the concern is.