I thought I would share the following as it gives you an insight into what is happening on most WordPress sites around the world; just that you are not normally aware of it. On your sites I use something called Sucuri Website auditing. It does a number of things, including logging activity on the site.
I have set up some sites to collect passwords from failed logins. The list below shows (probably remotely controlled) computers trying to login using the username “admin”.

They are using a password dictionary of statistically likely passwords to try to crack into the site through the administrative interface. Each also appears to be sent from a different computer. This is called a BotNet attack. A number of computers (probably hacked ones including websites) are attempting to login, On each login the IP address (think of it like a house address, it is in the form: 76.5.210.90) is locked out because the password was wrong, so then another computer takes over.
What can we learn from this?
Taking a line apart such as the bottom one it basically says that on the 29/01/2015 at 12:40pm a computer located at 78.6.9.150 failed to authenticate against the user name “admin” becasue they used the wrong password “viper”. Further analysis with an IP geolocation website tells us that this IP address is located in Rome, Italy. It also seems to be a known hacker source as well.
If you were to look up the IP addresses using GeoLocation services you will find they come from all over the world.
There are a number of security methods used to make this type of brute force attack on a website practically impossible to carry out.
Always use a hard password
Did I mention a HARD PASSWORD? Always use tough passwords for your logins. Most sites will not permit a simple password as there are checks handled when you submit your password. Now you know why.