It wasn't the forum's fault but the hosting.
Theymos claims it was the hosting. That's what you meant to say.
He openly states, in this very thread, that before any of the alleged social engineering took place,
"... The attacker was able to acquire KVM access credentials for the server. The investigation into how this was possible is still ongoing, so I don't know everything ..."
Not sure why everyone is acting like lax DC security is the issue,
The hoster denied beeing attacked with SE. It is still not clear how attacker gained access and why.
Possible, that the goal was to extract only a few certain PMs. This attack could be part of another, bigger attack. This also looks so determined to me, that I exclude email spammers, Satoshi seekers and random script kiddies.