Most attempts are automated
An attacker does not need to guess passwords manually. Automated tools can generate large numbers of login attempts against website forms, control panels and widely used applications.
Strong unique passwords, multi-factor authentication where available, limits on repeated attempts and monitoring for suspicious behaviour can significantly reduce the chance of success. Protection is most effective when these controls are in place before unusual login activity becomes visible.