ATTACKERS TARGET PEOPLE TOO
Repetition can be part of the attack.
If an attacker already has your password, they may repeatedly trigger authentication requests hoping you eventually make the decision for them.
Not because they defeated MFA technically. Because they made the person using it tired, distracted or annoyed. This is often called MFA fatigue or MFA bombing.
Repeated requests do not make a login more legitimate. They make it more suspicious.