I had the exact same issue. I launched a new droplet and installed Tomcat. Then got busy with other stuff. The next day I get an email that my droplet has been used for DDOSing. And am like clueless as it was a fresh droplet. I ask them more details about the attack but they do not reveal anything. I don't even know which files were responsible and where they directed the traffic to. They disable the droplet completely. The password for the server was their default created one so I don't think a security breach really happened. In over 7 years of working with plenty of hosts, this is the first time this has happened.