After a coworker's email was hacked, I revised my approach to login security.
I used to feel that two-factor authentication was too much trouble for daily tasks. Watching a phishing scam access my teammate's messages showed me the actual threat. Now, I turn it on for all work logins and advocate for our group to use it. This extra check has blocked a few login tries from strange locations.
But are those login tries really threats or just bots poking around? Most failed attempts are just automated scripts that would fail anyway. It's still good protection though.