Yes, I see what you mean.
Seems like the work they have done to get the site back after the hacking, have caused the web server security permissions not to be setup correctly.
Either anonymous need to be setup or the webroot folder is the problem.
Looks like they are doing basic auth firstly, which is not good, especially running over http.
I wonder if they asked for a restore, which can also cause problems like this, with permissions / auth specifically.
They just need to get in touch with their provider to have it sorted. They should know how to fix it.