Hi Eventualo
Glad to hear you’re looking at it.
It wasn’t intended as a criticism of your plugin, of course a hacker first has gain to access to WordPress admin which in this case seems to have been done via a vulnerability in an out of date Revolution Slider plugin.
https://www.wordfence.com/blog/2016/04/mossack-fonseca-breach-vulnerable-slider-revolution/
I run Wordfence on all my sites which reminds me when plugins need updating it also tells me when hackers are locked out due to failed login attempts. I was amazed at the number of bots that attack my websites with brute force login attempts!
In my opinion WordPress core could do more to improve login security, but that’s another story!
So two things for admins to learn from all this:
1. Make sure your admin account is kept very secure
2. Make sure to keep WordPress and all plugins completely up to date!
But you all knew that, right!
Stay Safe Out There – All the Best
Basil