

If you’re already using cloudflare, I’d recommend a cloudflare tunnel to your reverse proxy.
As was said, many ISPs will block port 80/443, but they won’t be seeing it that way with a tunnel. You’ll also get some cloudflare protections in front of your services.
The reason you didnt list, but is the most likely answer in my experience - by spamming the user who was compromised, they will miss the orders placed using their account info, or the password reset, or other such emails.
You aren’t the target so much as the distraction tool for their other efforts.