Quite a few years ago, a Network Manager for a major high street retailer with whom I worked tried to evaluate how true this was. As I recall, he used a laptop, NetStumbler (for sniffing out WiFi APs) & Ethereal (for packet analysis). He said that it was possible but not trivial.
I suspect that there are better tools available nowadays but on the other hand, fewer ISPs are offering 'wires-only' contracts for home users and the Modem/Routers tend to come pre-configured to be reasonably secure.
Very little Googling will suggest that you hide your SSID & set up a MAC filter list. The former doesn't make much difference but to bypass the latter, you need to identify the MAC of an approved device using traffic analysis and spoof it - easy but not for your typical casual user.