Is this just a static site? Or did it have known attack vectors like a insecure Wordpress plugin. Unfortunately this is giving me more questions than answers the longer I try to understand if this ‘hacking’ is just defacement or something more nefarious.