Earlier quoted context omitted.
It depends if this attack is on basecamp.com or the IPs that basecamp.com resolves to. It appears Basecamp only has a /23, so even if they redirected traffic through Cloudflare, the attacker could still find their direct servers fairly easily and attack that IP. It's still possible to block, but not quite as easy as setting up Cloudflare.
...the attacker could still find their direct servers fairly easily and attack that IP. Can the upstream to the actual server restrict traffic to known Cloudflare blocks?
The ISPs will help during a DDOS but response times are slow and we haven't tried getting them to put this type of block in place yet.