> Banning an account because you saw it make 20k requests to your API adding domains seems pretty reasonable, and it was a few hours before they reached out. If you saw that activity, would you ban the account or leave it open hoping that they'd be doing something nice and reach out?
If I was a domain reseller, adding my 20k domains to digital ocean just to get banned without warning, explaination or option for reconsideration I would be rightfully upset. If they didn't want people adding large numbers of domains they could just have limited the feature instead of banning people who reach some arbitrary threshold.
If on the other hand the department that executed the ban knew that the registrations weren't made by the domain owners, they should be discussing such a huge incident with the security team. That discussion would naturally lead to them knowing about the specifics of this case, unless this case wasn't widely shared in the security team.
So the options are:
1. Digital Ocean bans legitimate customers without warning or option for reconsideration; for no obvious reason
2. Big security incidents don't get reported to the security team
3. The responsible people thought that this was not a big security incident
4. This incident wasn't discussed in the security team
5. They knowingly banned a white hat hacker (who may or may not have gone too far)
Of all those options, the last one is by far the one that looks best for Digital Ocean.