Wow accounts have been getting hacked for years ( most of the time due to trojan people download while visiting mods sites), this is hardly news ( being the top guild on my wow server 3 years ago we had one member hacked a month on average, always those without authenticator..).
The only answer is like someone said earlier in this thread to get an authenticator...
As for stealing sessionsID I don't see how it would work, D3 uses the same authentication server as Wow..
The first time you log from a new IP the game always asks for your authenticator code if you have one attached to the account...








