We're going to see a lot more of such attacks (Denial of Capital?) as engineers blindly throw more and more SaaS components together without any sort of rate limiting in place, especially so when those endpoints are publicly accessible and tied to your account (e.g. Firebase or Algolia requests that are billable to your conveniently included client-side API key).
And in all honesty it's a lot easier to take a site offline through depletion of budget than trying to exhaust an infinitely-scaling service.