This is not as unlikely as it may seem, particularly since his domain name it likely to surface within the hackers community. Recently my friend used kiddie hacker software to to find exploits in vBulletin, it wasn't fully patched, but I was still shocked. It also depends if the mods he's used (if he has used any) have been security tested.
you surely of had to do something to jeapordize your license info.. i mean it doesn't get up and install itself on other peoples domains