First step is changing your password, both for cPanel in case that is how they got in, and for admin pages of your site if there are any. If you have more admins, make sure they change as well.
Next step is to make sure the scripts you have are up to date to make sure there are no security holes.