Use a strong (meaning LONG) pass phrase for all accounts. Fifteen characters, minimum. If they're not trying to break the Administrator password, you can enable auto locking of the account after so many failed logins. But that will lock out the real user, too.