I didn't see any response from Joe.... Did I miss something?
All our passwords are multiple character types, not straight dictionary words or even just random letters. But we did not enforce minimum length, now we do.
When checking older logs, I did find an ancient brute force attack against user steve on
ftp. Turns out FTP does not log successful logins in auth log, just the ones that fail. (Old version of FreeBSD). Newer versions are better. When Joe gets that Freebsd script out we'll just upgrade and migrate everything.
Still doesn't explain why the attacker tried "admin" first 1 time and then hit "steve". Either they thought they had a password from before or they were just adding some misdirection.
Steve