Ditto. I find it hard to believe that receiving 30 attachments in quick succession would trigger an IDS. People do that sort of thing all the time (try playing with "git send-email" sometime).
My guess is that it was more like 300, and cc'd to a bunch of external addresses such that it looked like spam.
So macspoofing: what did you have to do to get the account reenabled?
I bet that uploading a bunch of files all at once could trigger that lock.