They were almost certainly impacted by the recent sudo bug, considering how they offered cPanel hosting: https://archive.is/PCZ99 I've been trying to make contact with virtual hosting providers over the last few weeks to bring the weakness to their attention, but I've been ignored. cPanel hasn't even issued an update. It's heartbreaking watching websites get destroyed by the bad guys.
As a tip for the future, in case you're interested: you can use hn.algolia.com, search "sudo", time window something like "past month", and you'd have found it.
It is much more efficient and future-proof to have someone put the exact link as a reply, that way people coming to the thread afterwards can simply click on.
Though they would have had to also get into the admin server running (probably) WHMCS.
The sudo bug would let a hacker take over a server where the customer code ran, but not the main admin server. They would have needed some other weakness to get that. Perhaps aided by owning one of the customer servers.
It's possible they don't have updates running on a cron. It's also possible they got hit in the day or so between the announcement and the automatic installation.
It's even possible that while this seems to be a very likely attack vector that the attacker used something else. One place to look if they had a billing system hit and all their hosting systems is if maybe the billing system got breached first. There are automated provisioning and C&C things built into, say, WHMCS or WHM Autopilot that would be an ideal vector to all the hosting servers if someone breached the billing and provisioning system first.
I don't know how many different individual hosting systems we're talking about. Having a user account to use the sudo vuln on each and every one of them and then also breaching the billing server seems unlikely. It seems more likely the centralized tool was taken over (perhaps using one or a few hosting systems as a springboard) and used to spread to all the hosting systems automatically.