1,766 attempts to get into my website. None got in.

Call me sad, but I spent some time going through 12 days of security logs from my WordPress site. There were 1,767 events in total. One of them was me logging in. The other 1,766 weren’t.

Period  12 days Events  1,767 Successful break-ins  0
Grid of 1,767 squares, one per security log event over 12 days: 1,306 failed logins in coral, 460 other events in grey, and a single green square for the one successful login.
One square per log event. The green one is me.

What was in there

1,306Failed logins
226Tries using my name
23Automatic lockouts
0Successful logins

1,306 failed logins, which was 86% of everything. The username tried most often wasn’t admin. Scarily, it was mine, 226 times, before the generic guessing even started. Nobody found my site by accident. They came looking for me by name.

There were 23 automatic lockouts, with one of them impacting me directly. On 25 September, over a 78 minute period, 17 different machines from the same block of network addresses each took turns knocking at my website door. Each one failed and got locked out, triggering the next one to step up. I have since discovered that it was a botnet, passing the job between compromised machines so no single address got blocked for long. Luckily, there were zero successful logins.

I checked this three ways: no success flag on any event, no user ID attached to any of the brute-force attempts, and every lockout was my site security plugin keeping something out.

Is this a lot of attempts?

Good question (I said to myself), so I looked at the published figures.

MeasureIndustry estimate (12 days)My site
Attack attempts, any website~172 a day, about 2,064~147 a day
WordPress admin probesEvery 22 to 32 minutes, 540 to 7801,306

Industry estimates say the average website sees around 172 attack attempts a day, which works out at about 2,064 over 12 days. I came in a bit under that, at roughly 147 a day. For WordPress sites specifically, though, estimates say the admin area gets probed every 22 to 32 minutes, which is 540 to 780 attempts in 12 days. My login page took 1,306 on its own, roughly double the top of that range.

A one-person site with nothing worth stealing got more attention than the typical WordPress install, and I think being targeted by name is why.

What I took from it

  • 01

    2FA did the heavy lifting

    Every one of my own logins went through the second factor, and none of the 1,306 attempts got past the first gate. If you do one thing to your business website this week, set up two factor authentication for your logins.

  • 02

    Your own tools can look like attackers

    Some of the attacks were the security plugin running its own background checks. You need to be able to filter these out to remove noise.

  • 03

    Being safe and proving it are different things

    What holds up is the evidence: the logs, the lockout timeline, how you checked.

Things are moving fast

Attacks are shifting from fixed scripts to AI-driven tools that adapt as they go. They look for weaknesses on their own, dodge bot detection, and rotate through hosts exactly like the ones I saw. It keeps getting cheaper for the attacker.

There’s nothing of real value on my site apart from my own work, but this has been a really interesting exercise and I’m going to keep watching. I have set up my local AI to review the logs periodically and tell me when I need to tighten things up.

Using AI to defend felt like the obvious answer when AI was being used in the attacks.