The difference is whether it can be fixed. An expired domain is hard because we don’t actually know the attacker isn’t legitimate until they misuse the domain. In the case of hosting hijacking, though, the domain still has a legitimate owner, and the hosting provider is giving somebody else access without that owner’s permission. I’d blame the domain owner if they pointed their domain off at some malicious host, but the point here is that it’s hosting providers we consider trusted and legitimate that are doing this, and they can stop doing it, they’re just choosing not to.