Any WordPress site I managed, I make sure that my password strength is strong and updated frequently so anyone trying to gain illegal access receives a login limit exceeded error message.
Once the error message is shown, I’ll receive a text message or email with the attempted usernames and passwords along with the IP Address, OS and browser used and can either block the IP Address if from a residential network but the entire ISP if from a hosting entity as those are scripts running on servers and there are no valid reason for external servers to be contacting public facing servers that I managed.