The only way this attack would have worked is if DigiNotar's private key, whose public key is included in the major CA whitelist in major browsers, signed the domain. So either they did it, or somebody stole their private key. Either way it is very much their responsibility.