Naoki has already made changes to prevent this type of attack from working again (e.g., removing credit cards from Paypal, moving his domains from GoDaddy, etc.)
Hopefully the attacker didn't back up a decades' worth of his emails.
The attacker never got access to the victim's email accounts. He changed dns records to point to a different server. So he would have gotten some new email emails during the time he had the MX records pointed at his server (and he could have used that time to gather additional information), but he couldn't get to any existing emails.
Where there is a will there is a way. It's easier for an attacker for find a way in than it is for you to secure everything. The point is the attacker has the edge when the name of the game is, for lack of a better word, terrorism.