It seems the running spambot signups from Sendflood (sendflood.com/), a chinese venture specializing in... spam delivery (?), is escalating further. Now they're sending emails directly to the support addresses of instances, trying to get direct instance access. Of course there is no imprint or contact address on the page.
Anyone else got these as well?
Anyone got actually working mitigations for this (except LUA filters in nginx, hacking into the ruby code, setting up low-level database triggers etc.) that don't feel like playing whack-a-mole?