#29 - Aug. 10, 2010, 8:13 p.m.
I'd say one of two things happened here.
The original poster does have malware that connected with the compromiser instead of us - and they used that brief window of opportunity to log in.
The compromiser was given the code needed to log in at the time of that attack.
There really are no other options with a physical authenticator.
If it's malware based - it's vital it be found and dealt with. What we've seen of these cases to date (and they are rare for WoW - and hard to pull off) has normally been connected to downloading addons from fake sites that include fake launchers.