Long story short... I am the legitimate registrant of a xx.xx ccTLD domain via 1and1.com. I discovered today that the domain has been fraudulently transferred away.

This is a quote from the receiving registrar:
"the transfer of the domain name xx.xx was requested at the previous
registrar through Key-Systems by our customer in our automated system using a working authorization code."

I have since contacted 1and1 support who has acknowledged what has happened. They claim that they have escalated the issue to Key-Systems in the effort to return the domain.

Any idea where I stand? How this occurred? How it can be prevented in the future? The likelihood of a rightful return? Is there to be any accountability by my registrar? Is there any recourse with my registrar?

Thanks in advance -