Quite astonishing that someone managed to get valid certs from Let's Encrypt for domains that they didn't own. Has Let's Encrypt issued any statements about how this might have happened, and how those specific certificates were validated by them?
Still, good to see that monitoring the CT logs would have caught this problem much sooner.