There are some things you can do like:
1. Never use the same password for all things
2. System Up do Date
3. Up to Date software (web server, database, etc.)
4. Good AV's
I suggest you take down every web site for now and to a fresh reinstall to make sure you get rid of all the malware.
Also, I noticed you said most computers are running XP SP2-3, do you run your web servers on XP ?


