Through some social engineering, I was even able to get the name and location of the checking account owner and get him on the phone. I was actually quite close to visiting and beating the crap out of him. Turns out he was just some poor rube from Arkansas who answered a craigslist ad. In the end he was actually more of a victim than me (basically had his identity stolen, credit ruined).
Law enforcement at all levels were completely unhelpful (I dealt with CA police, AR police, and feds). Once I located the bank and got them on the phone, they at least were able to freeze the checking account (I believe they are required by law to do this once fraud/cybercrime is reported). That's really only a temporary fix though.
Any time you're doing payment aggregation or money transfers, you have to do as much verification as possible. We learned that the fraudulent charges had very predictable patterns (international cards, fake websites, very specific range of charge amounts, etc.). At a small scale, you should just manually verify all accounts, require phone/address verification, and more. I've seen some bitcoin startups that even require you to submit a photograph of your card + ID via WebRTC. This is what you should do right away. Once fraudsters realize they have to do work, they will move on to the next target. Our chargeback rate is now near zero and never fraud-related.
At scale, you can have in-house people write code to detect fraud patterns. There are also startups like Sift Science with APIs.
Hope that helps.