This is a common attack tactic, then, called MFA Fatigue. It also means they probably have Ops password already. Or Ops service provider is doing something dumb. (MFA requests shouldn't be sent out without the other factor being known.)
Edit: There's no approve link there. Just ignore these. If you got a lot of these, do setup MFA.