The fact that they had the details about the app pushing data through apns.spankapps.com means they probably sniffed the traffic when launching each of the apps on his phone, and saw that the device token that app was sending up was the same as the one from the leaked data. Pure conjecture, but definitely plausible.