We experienced everything mentioned above over the last couple of days. April 6th & 12th. It seems systematic. Once the accounts have been compromised. The hacking began.
Here’s a few more insights on what happened: https://www.abelcheung.org/advisory/20071210-wordpress-charset.txt
steps taken:
1. Changed the admin (level 10) account passwords
2. Deleted the ‘mysterious’ WordPress admin user
3. Upgraded most of major blogs to 2.5
So far so good. (crossing my fingers)