Looked at a previous thread & this is the answer from the plugin author
Files are modified when plugins are updated and when plugins perform certain functions. It is normal to see the /wflogs/attack-data.php in that list because that file is updated when your Wordfence Firewall is working.
Possibly just a false alarm?
Had email from client first thing who had email from 1and1.