Do you have WordFence installed?
This is a pretty common tactic, to use password lists and bombard a site with login and registration attempts looking for vulnerabilities and existing accounts. If they find an active account, the tactic might change. My WordPress sites that employ WordFence have tons of logs of these things happening.
|