It's not easy (I presume) to create such software. So why do they rely on some random e-mail provider? They could have done it so that computers unlock automatically after the address receives the payment. It's not that hard, the software could use multiple ways to get the private key (DNS, IRC, twitter, DHT) and it would be really hard to shut down.
Petya is ransomware-as-a-service, the author gives you the binary payload and unlocking service and it's up to the buyer to distribute / infect people. It often leads to poorly setup things like this where the buyer probably didn't expect their variant to spread so wildly.