2
           
            
                
     
    
    Verify in the database that your admin user has still your correct email address. If not, change. Then send you a new password with the lost password function.
Check out if no additional admin users or groups have been created.
For SQL change also your database password. Adapt it to mainfile.php. Verify also that no other users have been created.
Find out how the site was hacked, what was changed, reverse the changes and block the inroad, because changing the passwords is useless if there exists a way to overtake your site. The inroad can be older modules, complementary or managment site software, etc.