Ah, PR disaster handling
Cyprus-headquartered 000webhost admitted: "A hacker used an exploit in old PHP version to upload some files, gaining access to our systems. Although the whole database has been compromised, we are mostly concerned about the leaked client information.
"We removed all illegally uploaded pages as soon as we became aware of the breach. Next, we changed all the passwords and increased their encryption to avoid such mishaps in the future. A thorough investigation to make sure the breach does not exist anymore is in progress."
What they actually said is that they made their website ages ago and never updated it, so they were thoroughly pwned. Now, they are pretending to do something to cover the issue.
The investigation is simple : an old PHP exploit should not be allowed to exist on an ISP's website. An ISP should be well aware of best practices and apply them rigorously.