going back to this reply Ken has made. apparently their website was made using WordPress. to make matter worse, their WordPress admin login page is exposed wide open to the public. meaning that anyone can visit their admin login page and gain access to their WordPress cpanel.You mean like these guys? https://member.tnm.me/
for anyone wondering, if a wordpress site doesn't lock/secure its admin login page then anyone can easily take over the site by typing wp-admin at the end of the site's domain. for example:
example-wordpress-site.com/wp-admin