We've been knocking back an onslaught of automated "sign up bots" that cause numbers like that. Blocking them in the firewall has become a full time job! 8)
It seems like without geo-IP blocking the most useful directive is the following in .htaccess. order allow,deny deny from all allow from noone