Dozens of new Members (under Admin/Members & Groups) have been mysteriously added to one of my EE sites, which I did not authorize. Many of these members have activated themselves. I am the administrator and my client does not have the ability to add new Members. So my site must have been hacked.
I looked into the database info and each member field has spam content in it. I upgraded from 1.6.8 to 1.6.9, banned new member registrations, and changed my password.
Does anyone know how this happened, and are there any other steps I should take to prevent it from happening again?