No it was internal facing behind cable router. There must have been some vulnerability in the pinhole or os. They breached the router
But I agree that there's something other that's not ok. Compromised client (probably a computer) or a compromised router is my guesses.
It's stealth and has mitigations for DOS attacks.
I already run PiHole, but I might run this on a different box just to keep things simple.
Also, last I checked - port 51820 is reasonably well known, is it safe to use this default when forwarding traffic?