I'm wondering what 'seekcy' is. Possibly a Chinese security product?
$ journalctl | awk '/sshd/ && /Invalid user/ && $6 != "from" {print $8}' | sort | uniq -c | sort -bnr | head -n 30
34 admin
26 oracle
21 postgres
20 user
18 test
18 seekcy
17 ftpuser
15 ubuntu
15 inspur
9 zabbix
8 nginx
8 mysql
8 jenkins
8 hadoop
7 server
7 nagios
6 teste
6 amax
5 support
5 backup
5 administrator
4 git
4 demo
4 a
3 zyfwp
3 usuario
3 tomcat
3 testuser
3 test1
3 teamspeak
Googling it points to a Chinese IoT company, so I am thinking maybe they have some IoT software with known vulnerability where they have seekcy as the ssh username that is being actively scanned for.