Did you use nulled themes or plugins? Did you use the same password you use on other services? Was the hack through the hosting account itself, or the WP login, or through a backdoored WP script?
I personally use WPS Hide Login and WordFence, though these will not help at all if the issue is with your hosting or backdoored scripts.