If they keep getting the password wrong, changing the password isn't going to solve anything. If you password sucks because it has been in another leak (even if not attached to you), change it, but that advice stands even if you hadn't had someone trying to reset your login.
You said Authenticator requests - does that mean on your Authenticator app? Or just the email with a single sign in code? The former is the second part of a 2FA, so that means they actually do have your password. If that's the case, change your password and change it anywhere you reused it.