Check your office and home PCs for spyware or toolbars.
Make a list of all commercial software you have on the server, and very closely check for any known exploits. Often it is something as stupid as an old wordpress install that can get you screwed up. Make sure all of your software (including version of PHP and such) are 100% up to date.
Have your hosting company check your install of apache to make sure that it hasn't been screwed with. That has become a more and more common hack as time has gone on.
|