I counted 36 plugins, as previous stated, there were likely breaches found in a number of plugins.
Duly note, I'm currently overseeing around 250 WP installs, I haven't had a breach issue in years since I've been using iThemes Security Pro + the free version of Sucuri.
My admin login URLs are all changed to random characters.
Login authentification demands users: (a). solve captcha and, then (b). go through the 2FA login process.
To expedite the process, have your host scan your site to find the breach(es). Once you find and delete them, you might want to consider iThemes Security Pro + Sucuri.
Keep us posted.