Sometimes they get in simply by guessing the password (dictionary/brute force), especially if it was something simple. I had my ebay account broken into once. They posted an expensive swing set for sale. Why a swing set? Who the hell knows.
I also see bots hitting the servers this site is on all the time. Luckily they're protected. Their intention is usually to break in and 'do something'. Usually the purpose is to make a server a spam e-mail drone.