Now that we've come to this point, I remember a recent post of @themarkymark exactly on this topic.
The timing is uncanny. I wrote the post as a few users lost their account to ransomware and I was talking with a few other witnesses. I think it is a big attack vector most people completely ignore.
Fortunately for @arcange, all the data can be replayed, but it is a very time consuming process if he has to start again at block 0 so it is just a huge hassle. I am curious how they got elevated permissions though, HiveSQL is read only for users.
If it's only the database he lost, then yes, it's only time and hassle to get it back to date. He mentions another backup off site, so maybe he doesn't have to start from block 0.
Yeah, that's something he (or the investigators) needs to figure out, or this can happen again.