the worst hackers are however those who never cause any damage to content nor ever change password just quietly enter and USE your site to set up phishing site ON your domain in an existing subfolder somewhere. how to find? visually check for files that YOU never made there are currently hacker(s) since many months doing exactly that - silently. always using more or less same files uploaded to manage their own site on your site ... some however remove these files used after use ended. hence only way to find is by verifying your OLD access log files