I set up a WordPress website for my kids' school organization and ran it for a few years. I installed a free version of WordFence, a security plugin. I was always astounded by the number of IP addresses that plugin blocked from all over the world. It seems like Russia, China, Ukraine, France and the U.S. were the most common culprits. And they were tons of attempted "Admin" logins with the usual iterations of passwords...
It does make you paranoid. But is it paranoia if they really are out to get you? ?