I know you are not using WEP, right???

Also proximity isn't that relevant. A dedicated attacker can have something like this

http://www.cantenna.com/
http://www.turnpoint.net/wireless/cantennahowto.html

or just pull up in a car

also it helps to check if the time on your systems isn't screwed (expired cert. problem)

was the email legit ... not one of those made look like login screens which will re-mail your auth info to the attacker