Whether you use WP.com or self host, there is currently a huge attack on WP going on.
If you have a WP blog and have not deleted your Admin user, do so now. You'll need to create a new user, log out of Admin and back in using the new user and then you can delete the default Admin user that is created when you started your site.
And here's some advice from WP about chosing a strong password.