Sure, but he can't know that that particular app was the culprit with only that information because every app which has ever been installed on his device (barring a complete re-installation without restoration from backup) will send the exact same token.
The only way to blame one particular app would be if that app were the only app ever installed on a device whose identifier appears in the leak.