An interesting read about the "rules of engagement" (or rather, lack thereof) when dealing with Joomla websites:
http://www.itoctopus.com/10-reasons-why-your-joomla-website-got-hacked