this sounds like a tooling issue on their part.  they should be able to pick a specific set of items and trace them back and mitigate some set of spoofed packets.  Some attackers are advanced and will detect when you block their spoofed packets immediately (they have telemetry/data like we all do) and move to another attack vector.

You need to talk to the security team in their NOC.  These are usually small and sometimes difficult to reach.  I know our NOC can find them quickly and works with them on customer issues often.

Absolutely.  Even if the "lost costs" have been just payroll which already exist, this may be related to other activity.  I suggest calling your local FBI office (assuming you are in the US).  They can be quite helpful.  If you don't get somewhere quickly, let me know and I can try to hunt someone in a local field office for you.

I'll say it does matter, because even if they are in some "unreachable" location, these folks sometimes travel to locations where they can be picked up.  It may not be immediate, but can help build the case.

It is sad, but I can likely guess who your upstreams are, and some are more responsive than others.  I'm aware of one that puts almost no effort into tracking spoofed packets to clamp down on them.

