Managed hosting will secure the server, but you are still responsible for securing anything public-facing that you put on that server.
If your application stack is compromised, and used to host phishing sites, the hosting provider should send you related abuse complaints and work with you to secure it.
Now, this is just a theory on my part, based only on what you've said, but is there any chance that your (probably hacked) server was used to spear-phish the hosting company itself? If so, it could explain their reaction.
Hey, thanks! It’s hosted right now to keep it simple, but i may end up releasing an open source version for others to run locally if there's enough interest.