Hopefully next time they dont demand name.com reveal private whois or something else. Good on them for not suspending the domain/user, but this was NOT the customers problem. They had a legitimate website and you chose to take the easy way out. You should not have asked the customer to leave to another host, you should have fixed the problem yourself.
It is your responsibility as a infrastructure provider to have adequate DDoS prevention in place. Passing the buck to every extortionist that comes in is not acceptable behavior.
Now that people know that name.com is easy to push around, I suspect much more of these attacks will be likely. Best not to use name.com nameservers apparently.