Jack,
I have limited knowledge about this sort of thing, but I think it has less to do with the fact that they break into your server and more likely it is a virus that can steal the identity of someone in your e-mail programs address book, meaning if you (or anyone) has sent an e-mail to the site and it's in their address book the virus e-mail can disguise itself as coming from you (or anyone in that particular address book). In any event I don't think it is people breaking into your server, plenty here more knowledgeable than I and I would like to hear their response.
Penguinfan