It’s quite common to see repeated failed login attempts — bots often scan WordPress sites trying common usernames like “admin.” You can install a plugin like Wordfence or Limit Login Attempts Reloaded to block IPs after a few failed tries. Also, make sure to disable the default “admin” user, use a strong password, and enable two-factor authentication for extra security.