Some of the rumors floating around point to joining a public game (which gives the hacker access to your session id, which he can then spoof) as being all that is needed to be hacked.
Maybe true, maybe not, but I'm not going to go try to find any new friends until this dies down.
Another rumored cause is people infected with malware that lets a hacker use their PC as a proxy server to bypass their authenticator which is configured to "not ask every time" mode, the hacker would be able to login without authentication because the request is coming from the victims own infected PC.
Personally, I think this is a huge risk to blizzards reputation, I sure hope they are willing to admit if the vulnerability is on their side, and get it fixed soon. Personally I think this seems way too 'big' to be a bunch of schmoes with PC's loaded with malware, but it would be possible they have been saving up a big list of targets, as battlenet accounts were around long before diablo3 launched, and there is likely a large intersection between diablo3 players, wow players, and SC3 players.