There are more and more people being hacked that I'm seeing. Personally, I have gotten 8 now seemingly legit (as in actually from arenanet or guildwars2.com, truly) emails saying someone requested to change my password, which a confirmation link. DO NOT click that link if you did not request it. If you do, you can kiss your account goodbye.
When you change your password via account.guildwars2.com, there is NO email confirmation link. I'm not sure how they faked arenanet or guildwars2.com's stuff, but I'm willing to bet that this is the source of at least half of why various people got hacked.
EDIT - These are legitimate emails from Arenanet, they come when you click "Forgot Password" on the official website. I have never once clicked that, and still have gotten 8 of these emails. Do not click them unless you actually click "Forgot Password" on the official website.