I think you just answered your own question there. Their ddos mitigation plan was to block overseas traffic, which they self evidently didn't test sufficiently. But even if they did get that part right, that is a rather blunt sledgehammer which is going to both impact legitimate users (on VPNs, tor and possibly even those using overseas DNS servers) and is useless once the attackers figure it out as they will just switch to a botnet built from compromised Australian addresses or attack other infrastructure like Telstra/optus/tpg/iinet DNS servers.

