Something like this would show up in perimeter network/firewall logs correct?
But if someone was mirroring traffic to the same cloud provider you deploy in, it would be less obvious to find out _which_ set of cloud IPs aren't actually your own.
Do big clouds have a solution for this? I don't usually use GCP / AWS so I don't know what they have