> The attacker gained a root access to the server for ~40 minutes
and
> All data on the website server is encrypted. Manual actions are needed to make this data readable, so the attacker could not gain access to the data even when having a server console access.
Unless the "encrypted data" is simply being stored on that server, and not used, this seems like a hopeful statement to make. If a server process is accessing it, then it must have the key, at the very least, in memory (which root can access, though finding the key might be somewhat of a feat). Even if the truly valuable stuff was on another server, could the hacker not masquerade as the webserver itself, and make requests that appear to have originated from the webserver?
Granted, this assumes a lot about the ability of the attacker. I'm mostly saying it's possible, not that it's probable; the latter is harder to determine. Good see them rebuilding on fresh hardware: better to start from scratch than to try and "uncompromise" a system. Shame on the provider though; I'm curious to know who: I feel like such situations deserve a bit of name-and-shame, as they represent a very severe failure on the part of the provider. And the provider should detail very clearly what steps will be taken such that this will not happen again.