I've just had to recompile the leaked database to establish just how affected I am personally - 7 different accounts, phone numbers, addresses, payment transactions - fortunately no credit cards.
However, 12,735 (quick SQL result to find clients with last 4 card numbers in db) individuals with card details stored are not so lucky. One of whom is my friend that I recommended WHMCS too.
Oh boy, not impressed.
WHMCS is not all to blame in this but a better relationship with a new host who observes proper and custom security protocols is a must. Social engineering scams are a reality but they're never fun on the receiving end.