THE PASSWORD WAS CORRECT
The login can still be fraudulent.
Think about MFA from the attacker's side. They have your username. They have your password. Both are correct.
The login reaches one final step: approval required. At that moment, your phone becomes part of the security boundary. If you approve the request, the system may reasonably conclude that the login is legitimate.