About 3 years ago, our instance got shut down over the weekend because a spammer in Germany reported it for serving an 'infected' file while attempting to advertise their MX scanning service. Said file had a false positive in ClamAV (common for Windows EXEs) and only ClamAV. Digital Ocean shut down the production instance with no warning and then told us about it via ticket. It took hours to get a response and when we finally did, the instance could not be restarted (DO at the time had a bug where the kernel indicated in their admin had to match the kernel in the image or it could fail to start). Total downtime was 2 days if I recall correctly. The security spammer took out our instance 1 or 2 more times before DO finally either blacklisted them or correctly noted that it was a likely false positive. I got a few months credit for this issue at the time.
About 2 years ago, DO had an issue where they shutdown networking to our production instance because they detected a "Brute Force attack" originating from that instance. The detection was due to an increase in downloads because we'd released a new version of our software coupled with, yet again, a false positive in ClamAV (and only in ClamAV)... though in a separate copy of software on the same server that had been released a month prior. This also happened on a weekend and took hours and then a couple days to resolve due to the aforementioned bug at the time of DO instances failing to start due to the kernel in use within the Droplet not matching the kernel indicated in the admin.
In both of the above instances, a single support person killed the instance without pinging the customer first. This is to be expected from any mostly-automated lower cost provider. Contrast this to a Rackspace managed cloud instance where they will first contact the customer when a detection occurs or a false positive shows up in an antivirus scan. Of course, that's comparing our managed cloud instance at Rackspace to a self-serve low-end droplet at Digital Ocean. Why the difference? Likely because you'll pay between 3 and 5 times as much for the same level of server between the two providers.
As a result of the above, I kept our production servers at Rackspace but continued to use Digital Ocean for secondary services. We have backups for those services on DO and the ability for our product to fail-over to the backups automatically should an issue like this occur again. We have been considering moving more services to Digital Ocean as they appear to have ironed out the kinks of their first few years of operation now.