A small site on Cloudflare’s Pro plan has been repeatedly auto-blocked after a single person filed identical fake abuse reports six times since 26 September. Each submission triggers Cloudflare’s automatic “Suspected Malware” warning on the homepage and login pages until a human review clears it. The reports reuse the same text describing an “order” and product pages that never existed (404), include a file hash that doesn’t match its own VirusTotal link (which returns “Item not found”), and even contain date typos. Cloudflare cleared four incidents, but the reporter resubmitted the same claim within a day each time, leaving the site blocked much of two weeks, halving traffic, and causing Google to index the warning page instead of the site.
The operator has opened support cases and requested reviews for each incident, receiving only a single reply on 5 October with no permanent fix. They ask whether automatic mitigations can be suppressed for a reporter or repeatedly false text, whether a domain can be put into manual-review mode, and whether others have seen the abuse form weaponized this way and how it was resolved. The open support case number (02370521) is provided and the operator invites any Cloudflare abuse team member to respond.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.