It's important not to create new attack vectors that don't already exist when implementing security features.
If you don't throttle accounts that don't exist then a brute force attempt can be used to determine which logins are valid for a given service. This information can then be combined with targeted phishing attacks, etc.