I haven't. Smells like bullshit to me, but I could well be wrong.
I suppose if you change your password and don't go to their site, you're not running any risks whether it's real or not (unless they've infected you with a keystroke tracker and want to get hold of your new password, I suppose, but that seems rather far-fetched).