Email communicated with the hacker, as he was trying to get money from us. This is how he said he got in:
I exploited your site. Got that Admins HASH:SALT (which is the password encrypted). Once i gained acess i uploaded an AJAX code and upload a i47 shell. Then i looked at your config.php logged in to the SQL dump and dumped your database. Self killed the shell
I asked him to explain I exploited your site and he said "I ran a 4.2.x upgrade exploit."