That's one side of the issue. The other: where have such takeovers succeeded, and continue undetected, because the attacker did not (yet?) make a 500000-millisecond-blunder?
Absolutely. The framing around this is mostly about "when is the next one", but given the unlikely combination of errors and circumstances that led to this one being discovered, why would we think that it's the first time? It seems likely that this has been going on for some time, against various projects, and this is just the first to be noticed.