Hi Chris,
First, I suggest upgrading to the latest version of mojoPortal. Then, follow Crispin's advice. You can restrict your login page by IP through the IIS IP & Domain Restrictions tool.
I would also suggest changing all admin passwords to ensure they are secure passwords. I personally like Correct Horse Battery Staple: xkcd-Style Password Generator for password generation. Then, make sure you have mojo set to hash your passwords.
We also tend to use made up email addresses for sites we don't need to receive emails from. This makes it much more difficult to guess the login information. We just generate an alpha-numeric password, use a few of the characters for the user and the rest for the domain, slap .com on the end and that's the login. So 4p25NgFfrC6c becomes 4p25@NgFfrC6c.com. Whatever you do, your site login should not be the same email address that you share with the world.
Thanks,
Joe