What i would have done is:
- Secure my Admin password. (he said he cracked you in 2mins... use special characters,numbers and upper and lower case alphabets so it cannot be brute forced easily)
- Change my DB and FTP passwords.
- If you on a vps or dedicated get CSF firewall installed.
- Open a ticket with your host if you are on a managed host. Giving them the Ip's and asking them to check server logs.
- Rename Admin and Moderator panels.
- Add a password via htaccess for the Admin Panel.