I am assuming that they either set something up incorrectly, had a vulnerability. Whether it was a custom written script, or someone else on their shared server had a vulnerability. There are many ADP sites out there, and I have not seen one which has been hacked. (As Pavel has said.)