the security on the game is a joke. Everyone who has an authenticator thinks they are safe, but they are far from safe. The game uses a unauthenticated SID code to get into lobby and login servers, which is generated from launcher login. This SID string (obtainable via process list) lets you log in from any computer anywhere, its a long string but it is quite deterministic for those who know security stuff. Basically a very similar way to how hackers broke into Rift accounts at launch is present here, and while Rift fixed it within a week I doubt we'll see any fixes for this game. Someone can generate a valid SID string from one account, and then try tiny variations and get into any random account. If someone wants your specific account, they'd just need a way to enumerate the process list and hijack your SID key.
Really the only security at this time is to never logout, otherwise there are a lot of ways to get into your account and an authenticator does absolutely nothing. All the stuff about IP checking is done at launcher time, once you have your SID string it is valid everywhere and anywhere, another "security wut?" FFXIV dumb oversight.