I've had a forum once where something similar happened. After a week or so I got to chat with one of those guys on some IRC channel (I joined their community until I knew who did it) and it turned out they were just playing around with the newest exploit script. So they Google for some specific .php file (I had phpBB running at the time), enter the URL of that site into their script, and voila... you're defaced.
I asked him what the fun was, because it obviously wasn't the skills needed to be able to do such things. And he was laughing because all those forum dudes would have to restore and all that.
And that was all. I was high in Google and they found me before they found a few others. As soon as I installed a new release, I was all set.
So my lesson of the day was to keep my forum software up-to-date.