How can someone guess both passphrases, from separate wallets, in separate locations with different words? It's literally impossible.
Whatever technology is used to generate the passphrases in each of those wallets must be compromised.
Nothing else can explain it.