If you think that IP blocking stops credential stuffing you really are out of your depth.
Would it stop this guy if he was some skid just running Kali? Absolutely.
But it ain't going to stop anyone more determined. Especially since you're going to let those blocks expire to avoid blocking legitimate customers. A patient opposition with minimal resources will get by that kind of naive approach.
Not only that but you have 0 evidence they didn't IP block. They absolutely could have standard protocols in place but anything short of 2fa is inherently vulnerable.
I mean normalizing by dollar spent makes the list useful. It's not a "most units sold" list. It's a where is everyone spending money list.