At least in Tokyo I know plenty of people who are running PG on DO in a docker instances and just doing backups on DO cause its cheaper than something like heroku managed PG so if I was one of them (I kept my data layer off of DO) I would be completely destroyed by this. So I tell everyone I know now at meetups about this experience and so happy to share specific details.
They told me I log on from multiple locations (OMG I have a laptop and work while I travel, busted) and that I had a gmail address on my account.
The most agregious thing is that if their trigger happy "security and trust" flagger flags you, there is no warning where they reach out to you, they just destroy your instances, don't tell you about that either until you logon and are asked to file a ticket if you want your account unlocked...then a month later will unlock it for you but everything nuked.