Hi Ralf,
2.6.9+ now has protection against admin accounts sneaked in bypassing the Joomla user management.
These are now blocked immediately. At the same time, existing admin accounts are protected. Meaning: if the group membership—like in your case—is suddenly removed, it will be automatically reversed. Changes made the normal way via Joomla user management remain unaffected.
Luckily, HTProtect also catches the password of the new one, ...
The password isn’t exactly “caught.” You can log in via the dashboard as any active Super User—this creates a passwordless session for that user. The password itself is neither needed nor read.
Have you been able to find the cause of the changes on your end? Found any malware, is your database accessible from outside, or maybe a cronjob got injected?
Cheers
Pascal