The initial concern was that an attacker compromised vsys.host and set up a MitM attack using letsencrypt certs for ssl. This would have exposed passwords. That was not what happened.
The Ukranians had their WHMCS support desk broken into but not the servers. I reformatted anyways.
P.S. It's also standard practice to suggest strong caution in the event of any compromise.