FWIW, my account got hacked about 6 months ago, and I didn't get phished - also my account password was moderately robust... a word followed by a number combination...
After a good fight with my cc company, I got the $250 in charges reversed, and now have a combination of random letters, symbols, and numbers as my password. I will say that while the problem may not be widespread, there is some brute force attacking going on, or apples servers are getting hacked. Now that said, it would seem there are a couple of things they could do to beef up said security, such as allowing a user to identify a country of origin for their account, or even a series of MAC addresses from which to restrict access... that would probably be a lot of work, and too complex for most users to figure out though, and the problem may not be widespread enough to justify it...
Regardless, I was made whole by my cc company so no big deal - just a hassle...