What customer information did you store with that provider? Just names and emails, or was there anything else that attackers may have been able to access?
My email was also my domain name contact email, so I originally thought they'd obtained it by DNS lookup...