Yeah, it looks like I'm wrong about that. But then, I'd have to raise the question why MC hasn't done anything (successfully) yet to defend against this? They must be losing hundreds of thousands of dollars (per hour? not sure of volume here) because of the SecureCode payments failing all over the place. Also, a falling trust from consumers and vendors.
It seems mission-critical to get their site back up, but they haven't. I assumed that was because they couldn't. But if you say they can....why haven't they?
My guess would be that they incorrectly estimated the magnitude of any attack that they would have to deal with and are now scrambling to get a procedure in place that allows them to forward lists of 'known bad' ip addresses to their upstream providers to be placed in ACLs.