In either case you just wait for the attacker to reach daddy's credit card limit and then your site is back up.
Or get a different provider. Some are faster to respond. I had a false positive DDoS detection from netcup once (I was scraping an FTP site in active mode) and they automatically routed my IP through a DDoS scrubbing service, and automatically stopped that when an attack was no longer detected. I don't know what they have set up to be able to reroute a single IP globally like that - they agreed with some of their upstreams, to allow the occasional /32 for DDoS protection purposes.
Hoster is new to me too.
But I get it as a pattern. (If you dine at the party then you are a diner.)
Sure maybe you'll get lucky and they waive it.
But sometimes going down is a feature if you're not a multi m/billion dollar business