So according to the Board4All forum staff, there was a VNC server running on the hosting server which had vulnerabilities. This means that effectively, if anyone exploited that VNC server, they would have remote access to that hosting server!
I hope that this is not correct. If so, that means they have whole database. And In this case let's hope it is fully encrypted.