Akamai cached sites don't move between IPs. They are hosted on all of them. Anycast is used to direct your request to the DNS server nearest you, which then goes on to direct your actual HTTP request to the server nearest you. If the attacking computers are geographically located in a certain area, that area will suffer gravely, but other areas won't be affected at all.
As such, ANY Akamai hosted site is DDoS protected by nature. A few years ago, an iOS update was slugish to arrive. Afterwards, we were told that there were considerable slowdowns to web sites not hosted by Akamai. In other words, it was not that the Akamai network couldn't handle the load of many people downloading the update at once. The Internet couldn't handle that load.
There might be something technical I'm not aware of, but as far as I know, the DDoS protection product is a marketing thing, not a technical thing. You are, essentially, buying insurance against having to pay Akamai a whole lot of money for the DDoS traffic it served on your behalf. I am not 100% certain, but I do not think Akamai serve DDoS protected sites and regular CDN hosted sites differently.
Whether it is bad PR or not is not for me to say. I do think that a host provider that gives a pro-bono service has a legitimate claim to say that non-paying customers should not be costing it more than it is willing to give. On the other hand, I also agree that, in this case, the DDoSers won.
Akamai used to publish real time information on how much traffic the entire network was carrying. The page is still there, but it no longer carries that information. I don't know why.