Thanks @dennishermannsen for suggesting the vulnerability is in the Duplicator plugin.
I got our site back online by just going through the WP setup wizard steps and using the credentials for the same (existing) database. Setup then said “..already installed..” and the site was public again. That’s only a temporary fix and I’ll do a full reinstall of WP without Duplicator plugin to clean it out.