Looks like a PHP site. I'm guessing they weren't using version control and were instead just editing the files over FTP.
They may have been using version control, but if they were checking out to a server and editing remotely, and that server happened to be the same server where the central repo was stored, it could explain how one attack would get it all.