Someone recently hacked my site and i had to delete EVERYTHING and reinstall.. previously, they installed phishing files to use to send phishing emails to some bank customers in Canada and the UK. I think it was done by hacking the Joomla admin sign in page. when i recently re-installed, there were several attempts to login to the admin page from a couple of IP's in Turkey.
Be alert to this type of activity. if possible install on your site a secure method to somehow hide admin sign in some way. i am not sure if this is how they were able to get in.. probably new webmasters using joomla neglect to change the default Admin password or delete the default ADMIN altogether..