Persistent brute-force SSL VPN login attempts detected against our infrastructure
(Windows AD / CH ...
show morePersistent brute-force SSL VPN login attempts detected against our infrastructure
(Windows AD / CHAP authentication gateway).
Log analysis reveals this IP has been conducting automated credential stuffing
attacks for at least 2 years, systematically targeting accounts — including
users no longer active in our Active Directory.
Latest confirmed event: 2026-04-22 10:17:12 UTC
→ Authentication attempt on account "xxxx" via SSL VPN (CHAP, no token)
→ Result: account locked after reaching maximum failed attempts
→ Source IP detected through internal PAM/gateway logs
The IP belongs to ASN56971 (CGI GLOBAL LIMITED / cloudbackbone.net),
classified as Data Center/Hosting/Transit — consistent with an automated
attack infrastructure.
Attacks occur on a daily basis with no interruption. The fact that stale/deleted
AD accounts are being targeted suggests the attacker is using harvested or
leaked credential lists.
show less
Brute-Force
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.