If Amazon got complains about Heroku then I'd certainly expect them to be investigated, and in Heroku's case I'd expect Heroku would take over and shutdown the phishing site.
Also pandaform doesn't allow use to put any script or password field in the form, which the quality of the "phishing" form is not as serious as what we thought as a normal phishing site do.
I'm sure if Pandaforms had done this (which is difficult when you're a much smaller startup than Heroku) then their server would have been left untouched.
You can argue that Heroku would have most likely got a phone call and that Pandaforms deserve the same treatment, but I don't think that they'd have been allowed to leave phishing sites up for any period of time without their servers being placed in jeopardy either.
Once a phishing form is “in the wild,” every minute counts.
The burden is on the service (your site) to prevent or quickly act to rectify a situation, but if your provider determines that it must intervene, then it is well within it's right to.
Yes, if there are enough complaints and harm that may come from it is serious enough.
A second complaint, without any investigation, would result in the termination of his account and destruction of data.
That is not reasonable.
We don't know this. We have no idea how many complaints rackspace has against this guy. It could be one or it could be dozens.