Install Stop That Hacker and forget about it.
http://www.stopthathacker.com
It stops the brute force attacks before the hacker can steal your passwords 99.9% of the time. If the hacker is using HEAD attacks it can stop them 100% of the time.
And if a member gives his password out or a hacker buys a membership using a stolen credit card Stop That Hacker will detect password abuse and kill the password.
Then just redirect the bad password attempts to what ever page you want. Make you a small fake members area upselling the hell out of your main members area.
Hugs,
Danielle