Good post-mortem analysis by the registrar: https://news.gandi.net/en/2017/07/detailed-incident-report/ You can see what DNSDB know about one of the hijacked domains: https://gist.github.com/bortzmeyer/0c6c843a89b9e381ee9396e51c4461f1