Thomas' frothing at the mouth is inevitable because this is yet another opportunity for him to insist that DNSSEC is bad, but let's inject some realism.
This is a story about how some unspecified number of sites claim they were "hijacked" over two years but in which all the actual evidence available says they're just idiots whose registrar account password was stolen. "Iran" is mentioned, but to be honest "Script kiddies" is a more rational explanation.
For those new to all this, GOOGLE.COM was picked by Thomas because he reasonably suspects for most Certificate Authorities it's on their "High Risk" list and so they either won't issue or will use a manual verification process. (Let's Encrypt doesn't have a manual process, all High Risk issuances get "Policy forbids" responses). Your domains are unlikely to be so lucky.
But the rest is hyperbole. Sudden dramatic distrust is how the big scene in Rainbows End works, with the Europeans revoking everything under Credit Suisse to try to kill Rabbit. (I love the description of how Rabbit has never conceived of being surprised and so its default expression doesn't leave any room to actually portray the emotion). But in real life nothing so dramatic is possible.
Some time in the first 24 hours the Maxmimum Merge Delay means the certificate becomes visible to people other than your direct victims. That's the first time Google would know. At this point some of my friends at Google might get called. Tactically there are some immediate things they can do, let's assume they choose the most dramatic for Thomas' purposes. Chrome blacklist updates start switching off this one certificate. If you aren't using Chrome (and maybe web browsers aren't even the intended target) this has no effect. If you do use Chrome it make take minutes, or hours, or in some cases weeks to have any impact, the tail for such a change is notoriously long.
Probably in parallel, Google will reach out to the CA's 24-hour contact asking for revocation. If they don't have the private keys (and there's no reason they would) this will be a manual process, and on a good day I'd be astonished if it's done in less than an hour. In theory the CA has no more than 24 hours to revoke. In practice they _routinely_ miss this deadline. It may be days or weeks before the revocation happens depending on exactly what happened and when.
Google would also reach out to the big trust stores. All of them have some capability to blacklist a certificate, none of them can do it quickly and all of them have that "long tail" where it may take months to be completely effective.
Part of that "reaching out" would be raising an "Incident report" bugzilla ticket. Where Thomas imagines a "no notification or further intervention from you" sudden process instead the Incident would get publicly discussed over days and most likely weeks, with everybody keen to understand all the details of what happened and why before recommending any future course of action.
After a few weeks, assuming we decided that somehow the CA was culpable rather than being a victim too, the decision would probably be to impose more audit or other oversight conditions on that CA.
What Thomas conjures up as this Hollywood Action Thriller style sequence of events is actually more like how an aircrash investigation goes. The burning wreckage makes the TV news, idle speculation maybe for a day or two after. But the actual investigation doesn't happen on a TV news cycle, we take our months to piece together all the details, to get a complete story, and then we think about it calmly and we make recommendations. Drama is not what we do.