I know you are not using WEP, right???
Also proximity isn't that relevant. A dedicated attacker can have something like this
http://www.cantenna.com/
http://www.turnpoint.net/wireless/cantennahowto.html
or just pull up in a car
also it helps to check if the time on your systems isn't screwed (expired cert. problem)
was the email legit ... not one of those made look like login screens which will re-mail your auth info to the attacker
