even if dwolla lets you guess only twice, with enough compromised accounts, eventually you are bound to be able to guess correctly.
But it is possible that the perp did have access to the persons online bank account, or dumpster dove for a statement to confirm, or hacked an email account, etc....