I guess no one read the long reply. Apparently the I.P. addresses were spoofed. Therefore no suspended customers were involved in the attack.
Maybe you should put a couple packet filters on the Ciscos to not forward/route SYN packets from your personal IP range that are coming in over a peering link.