even if you see something like a single /32 address that is probably the public facing endpoint of a mobile phone carrier's cgnat and has MANY users behind it, trying different password attempts, you can still rate limit the number of attempts per unique username.
the actual amount of legit requests that a human who has forgot their password makes is 99.9% of the time under ten requests per account before they give up.