It's possible they don't have updates running on a cron. It's also possible they got hit in the day or so between the announcement and the automatic installation.
It's even possible that while this seems to be a very likely attack vector that the attacker used something else. One place to look if they had a billing system hit and all their hosting systems is if maybe the billing system got breached first. There are automated provisioning and C&C things built into, say, WHMCS or WHM Autopilot that would be an ideal vector to all the hosting servers if someone breached the billing and provisioning system first.
I don't know how many different individual hosting systems we're talking about. Having a user account to use the sudo vuln on each and every one of them and then also breaching the billing server seems unlikely. It seems more likely the centralized tool was taken over (perhaps using one or a few hosting systems as a springboard) and used to spread to all the hosting systems automatically.