Perfectly pulling off an actual MitM attack and then forgetting to renew the certificate is certainly a very German thing :-)
Or, someone very diligently followed the orders - there was an order to set up a cert, but there was no requirement that it has to auto-renew :)
So they were told to renew the certificate, but not how many times to renew it?
One obvious possibility could be e.g. sending a notification to the previous ACME account: "hey, a new ACME account request a certificate for your domain".
I wonder why this didn't.