You'd need at least a little bit of remote code execution on the perpetrator's machine to lift his MAC address. Not guaranteed, but plausible.
I expect the manufacturer to have a database correlating MAC address, serial number, date the device left the factory, and where (i.e. which retail store) it was shipped to.
I expect the retail store's inventory tracking system to know when the device with that serial number was sold, by which cashier, at which register.
If it doesn't know the (tokenized) credit card number and name on card directly, I expect the store to be able to find its copy of the receipts from that register at that time, which would contain the last 4 digits and name on card.
If the purchase was relatively recent, I expect video of the register at that time.
If the purchase was in cash but the video is still around, I'd also expect video of the purchaser walking out to his car, and (maybe separately) a shot of that car with good enough resolution to pick out the license plate.
I don't think Joe Credit Card Fraudster gets this kind of attention, but someone who is believed to be a credible national security threat... absolutely.