I have seen no data here or elsewhere that suggests blackhats are brute forcing [my] accounts. Although outside of my area of knowledge I would have thought that blocking more than 5-10 attempts for a login in a [second, minute, hour, day, month] would dramatically impact the effectiveness of brute forcing.
All the news coverage on password weakness seems to be sourced from the security failure of the vendor rather than individual user.