I was thinking about this and came to the following conclusion:
If this is legit then Amazon needs to be read the riot act for sending legitimate emails that scammers can mimic knowing that people have had some trust built that such emails are legitimate.
It's just a terrible practice to email people telling them to change their password. If they are really concerned about security then they should just lock the account and let the user discover it and rectify it whenever they try to log in.