I wonder if people are getting their email addresses hacked, too.
For example an hacker could retrieve their email address if it's used on another forum/site/"w/e", hack it and use the password retrieval system of SE to get a new password.
Whoever is using gmail could enable the 2 steps verification using the smartphone token, similar to the SE one.