If I was designing an attack, a high visibility, low persistence attack where I send my victims to a website not under my control (unless you're asserting the attackers also got control of protectmyid.com) would not be my first choice, especially if I'm spending the money it took to shoot that video and stream it to all the people who you ostensibly want to see it.
This misconception bothers me a lot. DNS changes are complicated: there's no "n" where "n = the amount of time where any domain will magically be fixed".
"Propagation" is based on the configured TTL values of the specific DNS records requested, for the specific zone. Add in layers of application/OS/intranet/ISP/DNS provider caching, and it's a complicated nightmare to fix/predict reactively.
Most BIND9 installations use 86400 seconds by default: 24 hours. And some domains use more, some less, some have dynamically generated TTLs to simulate changing of records at a set/recurring wall clock time, instead of a time to live, some DNS caches are reset frequently, some caches retain values much longer than allowable by TTL...
I get that they should have used SSL, it'd have been a good move. But you can't seriously use that argument.