Tracking every item back to who had what at any point would be an immense amount of data. They would do it, if they were responsible and held accountable for that. However they are not, and thus, it's substantially cheaper to tell users to be careful with their accounts.
A plausible hypothesis on how these are accomplished, is by hacking into various forums (possibly related to WoW) which have very lax security, obtaining user information, running scripts to see if any of those accounts are WoW accounts.. etc etc.
I've also read about trojans and the like coming along with various game mods, even from reputable sites. Remember, if it's all scripted, the people looking for the info just have to wait. The computer does the work for them.
A cheap option is the
Blizzard Authenticator, too bad it is currently sold out.
Click here for further details.Aside from what Blizzard says, I have yet to see the reliability of the devices, and the practical application of them.
--
:wq