We've also seen numerous cases of PCs infected with a virus that sniffs the outbout FTP traffic. Since FTP transfers all data, including usernames and passwords in plain text, this virus captures that data along with the IP address, sends it to a server in the UK and then carries out it's website infection injection attack.
We've been recommending that people use either SFTP or FTPS since these 2 protocols encrypt all their data making sniffing much more difficult (some say impossible). If your website is on a *nix box, SFTP is easy as you can use WinSCP and do FTP over SSH. If you're on a Windows box, you'll have to ask your hosting provider about FTPS.