>
Attackers don't do things that overtly "change" things... especially something that is visually apparent on public facing websites...Yet, for many, many years, that was probably the most common thing that attackers (including a much younger, teenaged version of yours truly) did. At that time, however, "defacing" web sites was done mostly for bragging rights and without malicious intent. In many (most?) cases, the original index.html page would be copied/backed up and the "new" web page (created haphazardly using vi, perhaps) would replace or augment it.
For a long time, there were even mirrors [0] of these defaced web pages. attrition.org ran one from 1995-2001 and, for much of that time, even ran a mailing list where they would announce these "defacements" -- often, immediately after they occurred (after being tipped off by the attackers). It was pretty common to be able to view the "still defaced" site while it was still live (before being taken down and/or restored). As a frame of reference, attrition.org stopped mirroring these sites in May 2001 [1].
> ... it will no longer mirror the defacements because keeping up with the volume and rate of hacks is too much work ... ([1])
So, yeah, it happened A LOT. It is, of course, a much different world now (although defacements still occur regularly).
[0]: http://attrition.org/mirror/
[1]: https://www.computerworld.com/article/2582627/security0/attr...