Quite astonishing that someone managed to get valid certs from Let's Encrypt for domains that they didn't own. Has Let's Encrypt issued any statements about how this might have happened, and how those specific certificates were validated by them?
Still, good to see that monitoring the CT logs would have caught this problem much sooner.
As far as I remember from when I last read that article, it was a police-requested MiTM by the hosting provider. LetsEncrypt did a standard challenge (requesting http://webroot/.well-known/something) and the MiTM responded appropriately. This isn't really a problem with LE - if you can control the http response to all outside servers, it's fair to say that you control the domain and should have the cert. Bad on the hosting provider for doing so? Maybe, but there is no way for LE to know.