Yesterday, there was a bot that made a ton of posts in different communities. The mods of ttrrpg.network banned that user, and about 20 other people were also banned from several communities each on ttrpg.network (including me) with the reason given "Account used to boost spambot account" (for me it was all the communities on that server that I was subscribed to, but I wasn't actually banned from the instance):

The mods also made a pinned post in that sub (it's unpinned now) where they explain their reasoning some more:
Just got done investigating a spambot we had earlier, and it looks like they used a lot of compromised accounts on other instances to give their post an initial upvote boost. If you don’t already, please remember to use a good strong password.

I do remember interacting with at least one post from that bot, to me it looked fairly innocuous until I looked at the sheer volume of posts they made since the account was created. I assume that I'd notice if my account was hijacked, especially while I was still actively browsing lemmy, and my password is certainly not easily to bruteforce or guess. I also took a look at the profiles of the other users who were banned, there were quite a few who were still posting or commenting after they were banned from rpgmemes - none of those profiles looked suspicious to me, and many of the ones who didn't post or comment anything since then just weren't that active in the first place.
Frankly, I don't believe that any of those banned accounts were actually hacked. It looks to me like the mods just banned everyone who interacted with that bot. I understand that spambots are a big issue that is difficult to solve, but fediverse mods and admins need to be a lot more precise with dealing with that than this - the cure can't be worse than the poison.
I did message one community mod of rpgmemes and one of the server admins about this, but neither got back to me.
Less PTB, more dumb admin with 0 logic.
i.e. CLM