Some of the trusted IP ranges configured for our organization were saved with a trailing space by accident in the range value. Because of that trailing space, those entries did not parse as valid IP Ranges in the backend. When an incoming connection was evaluated, the malformed entries prevented the client IP from being validated correctly against the configured ranges, and the connection was allowed through rather than blocked. This resulted in the client IP connect to the org despite falling outside your “Trusted IP” ranges.