When I returned from lunch today several of the users informed me that their accounts were locked-out. I went to the event viewer and found that ALL usernames/workstations had Event ID 538, 529, and 644, indicating that their accounts had failed login attempts and then were locked-out. The strangest part is that the domain is SEPEN as is the workstation name \\SEPEN01. That isn’t our domain, nor is that a workstation on our network. Any suggestions/explanations?