Ed: “the attack is going after an account that doesn’t even exist”
Does it have its own unique domain name?
If it does, you could remove it from DNS, which once the cache expires should stop them reaching the server at all (unless they’re using the IP address, rather than going via the domain name).
The security system automatically blocks suspicious site accesses, too many failed login attempts in too fast a time, too many failed logins over a longer time, etc. etc. Currently it’s disconnecting. I haven’t seen a single domain name, just random IP addresses.