A million password resets is shockingly low for a DDOS, could this have been an university assignment gone wrong? I can imagine some clueless dean ordering all their engineering grads to submit research to arXiv. If they have 100-200K students, a single poorly written script to link the institution's SSO with automatically created arXiv accounts could easily overwhelm the system.