We weren't actually hacked. They used an old (and apparently vulnerable) PHP script we were no longer using to overwrite the index.html pages on our site.
That's the extend of what they were able to do since our environment is extremely secure and the web server does not run as a privileged user.
If anyone has questions, Email
[email protected].