The IP doesn't fit the actions, they were under a proxy, so it still could have been the same guy. And the mod seems like a cool guy so I'm thinking it's more likely to be a hacker, we just wanna make sure. Also, by brute forcing not working, do you mean from the outside? I meant someone could have tried brute forcing his vBulletin password.
Thanks for your reply man.