Guard against this is quite simple, we recommend two simple steps:
1. Remove user with the login admin. By default, WordPress does not allow to change the login of the user, but it can be changed either through phpMyAdmin, editing table wp_users field user_login administrator, or by creating another administrator in the admin area to another login, and then authorize under him, to remove a user admin.
2. Close access to the admin panel. This can be done with .htaccess in the folder wp-admin to allow access only to your IP, or further recovery record this folder means webserver. There is a pretty good option - installation of the plugin Lockdown WP Admin, which allows you to change the link to the admin area and further her recovery record.
Following these two simple-minded recommendations you provide your wordpress site on almost impenetrable defense against such attacks, as well as reduce the load on your site, as attempts to brute force password create quite a serious load on the server.
If you will need help - you can always contact our specialists.