Correct me if I wrong, but if this lead - let's just call him David. If David originally existed in SFDC back in 2012 wouldn't he have been created in Marketo, too, considering both systems are bidirectionally synced? Then a user recently uploaded David's duplicate in MKTO (MKTO did not create a dupe), but SFDC created David again with the same email address.
If it's easier = So before the upload, there was a David in MKTO and a David in SFDC. Then he was created again (via MKTO) with the same email address which created the dupe.