If it was actually legit than this is an actual breach of Federal Law and a violaton of his Terms of Use Policy for his ISP
Apparently the stuff is botnet-based rather than vpn based, so the only thing taken down by his ISP, theoretically, is the CnC server that could give the stop command (or it could bring it all down without the CnC server active, who knows)