Hackers Use Large Botnet To Gain Access.

- Choose a very strong password - which is always a good idea.
- Change frequently used admin-level credentials
- Install a number of WordPress plugin like wp-fail2ban , Lockdown WP Admin, better WP Security, BulletProof Security or simply by hardening your WP by providing access to the WordPress admin console, to approved IP addresses.
- WordPress founder Matt Mullenweg notes in a blog post that changing your 'admin' username to something a bit more obscure may be your best defense given that the hackers have 90,000 IPs at their disposal.