It sounds to me like they've bypassed the security using a vulnerability & given themselves root, which then opens them up to do anything or put anything on there. eg give themsleves admin, create accounts or put trojans / other software on there etc.
I'm no expert, but probably the way forward...