Well, all the signs I saw in the last week leaned more towards software issues (our auth software being sluggish, which it was). But since the basically full rewrite on the back-end of our auth, the traffic was still very high, and causing connections to be dropped entirely for no apparent reason.
I implemented something new just recently (about 2 days ago) to start detecting people attacking our servers, with fake, or legit, traffic. Unfortunately, during that time I couldn't enable the automatic bans until it was stable enough to do so. However, that's been enabled as of a few hours ago, so we'll see what happens.
I'm aware that you guys would like more information on stuff like that, but it's not really something I can talk about until it's been "resolved". I'd prefer to prevent stuff like that from happening again in the future, and if the attackers catch on, they may stop entirely, so I'm out of luck.
I do apologize for the lack of communication, but it's one of those times where "less is more" in the long run.