I agree, the threat of a stolen database is the REAL threat. You get a trojan on your server that allows them to download your database, you're done. The SSL cert doesn't do anything except make ignorant people think that they are safe.
It's like hiring an armored car to transport your gold bars from the airport to your house, but once at the house, you lock the front door with only the door knob, which anyone knows provides very little security.
Adding to another point made by brianoz, we used to run our company site on a shared server running in Apache mode vice CGI. Eventually we switched to CGI mode and moved all the client sites off of the server, but years later I just now found trojans buried in our site that were years old.
SSL means nothing. Insecure servers will destroy you, and an SSL certificate will do nothing to help.
Believe what you will, as like brianoz pointed out, until it happens to you, you won't listen.
Paypal uses SSL, but is that going to save them if someone manages to get a trojan onto their server?