I've never had this before, but it could be more common that I've experienced.
Since Sunday my logwatch email has been reporting a few attempts each day to ssh connect using the users:
The originating IPs do not seem related.
Has anyone any experience of this or is this something new. Some kind of worm perhaps?