^ Not even close. But they got access to both, somehow, somewhere. And I think it started with the a mail account of one of the employees, looking at the logs.
I don't fucking know, long weekend of locking down wp installs in front of me tho.
Just talked to some wordpress guys. They say that changing version to 6.9 won't hurt, but it won't stop bots from trying stuff anyway. Problem with version 6.9 is that you can't do an automatic upgrade, so keep on top of it.
Anyway, I came by to share this presentation, from the guy who told me the above stuff: WordPress Security