Your account is hijacked because your password was weak enough to be guessed, or it was obtained through a keylogger, phishing site, or some third party forum/website where you used the same email and password combination to register. How is that weak security for SE? Choose a strong password that is not the same as any other, and activate a security token - which are FREE for smartphone/tablet users.