DNS wasn't really hijacked. They managed to obtain the username/password that allowed them to change the domain.

They probably got those credentials with spear phishing.