ah if they are using cloudfront, they must be using the AWS managed WAF rule, which is pretty bad.
I used that once and got in trouble with the client since the ruleset was over blocking.