Download speeds often fluctuate, it very well could be factors outside your network. Still, if you suspect someone is stealing your connection--log into your router and set up WPA encryption and be sure to choose a strong password. (I can break WEP encryption in minutes on my machine, so if thats how you're set up, change it) WAP is much harder to break, and requires that your password be suceptible to a dictionary attack.
Then, you'll need to change the settings on your network card so that it connects via WPA instead of whatever it was connecting with before.