> Unfortunately, according to trusted sources (ex-employees) of Hetzner.de, this is policy and not an exception. They have realized they can save money (by limiting attacks) by redirecting the attacks back at the person reporting them. That way, the hacker/cracker/kiddie using their services will not cancel their contract with Hetzner, and in return Hetzner will remain protected.
I don't think that this has to do with Hetzner needing criminal business but rather with Hetzner not wanting to shut down an entire server if a part of it has been breached. Forwarding that complaint in it's entirety is definitely not best practice however making such allegations is neither.