Yeah, I struggle to think of any good analogy that would help explain the problem. You could explain HTTP as like sending a postal letter where an attacker can intercept and read the letter undetected, reply back as if they were the receiver etc . but that's already pretty abstract. Drawing a real-world analogy with automated password attacks seems even harder.
"There's a gang around here that like to walk up to every car in the parking lot and try every door. They aren't targeting you specifically, they just try every door knowing that some doors will be unlocked. So always lock your doors"