Well on PHPBB your display name is also your User ID, so they have 1 of 2 pieces of the puzzle.
Dictionary attacks is when someone sets up a bot to continually log into a phpbb with a known username and basically spams the board with bad passwords. Currently PHPBB does not lock out a user after X attempts, with the new patch it locks out at X attacks determined by the administrator of the board. It can also temporarily lock instead of permanently etc...