It can happen if we noticed the membership change through AD sync of the group, in which case we know it happened, but can't tell by who.
If we got the event from the DC that used for the modification, we should also be able to tell who did it.
could it be that you don't have full ATA coverage in the forest or maybe if Standalone gateways are used, events are not forwarded to them?