Why do you presume that debit card PIN numbers are stored on the card? (They aren't, as far as I know - how else could you change your PIN over the phone or on the card issuer's website?)
Sorry, I should have been more clear. PINs have not been confirmed compromised in any reports I've read so far, but it's been mentioned as a possibility. If magstripes were transmitted/stored by Target to perform the authorization, then it's possible that PINs for debit cards were transmitted/stored as well.
He's not presuming the PIN is ON the card, but that the transaction was the point of compromise (i.e. you punching in your PIN and the software running a verification of if that PIN is correct).