Comment There is an article to explain further findings (Score 1) 9
The SEC filing indicates that the attacker had access to user email addresses and customer numbers, the original WordPress Admin password that was set at the time of provisioning, and SSL private keys.
Link:
https://www.wordfence.com/blog...