A friend with a great deal of experience tells me the indexing of website cannot be turned off and is part of the w3 standard.
Indexing can be turned off, there is no standard to my knowledge which dictates that directory indexing must be enabled. Security by obscurity provides little in the way of protection.
If someone has accessed these 'hidden' files perhaps they knew the correct URL in the first place. Does the attacker try to guess the URL or do they go straight there?
Jimbob