Their comms people have made a bit of a balls-up of this.
Like most people I was suspicious of the first email, even though it passed basic checks. They have obviously had their heads in the sand and do not know what a phishing email looks like, and have underestimated people's awareness of phishing emails. Otherwise they wouldn't have sent out something so obviously dodgy looking.
Anyway, if you get an email from a company with whom you have an account, even if you are expecting the email, don't click the links in the email. Sign on to your account separately and do whatever is needed from there. If you get into this habit you're less likely to accidentally click a link in a phishing email. The exception to this is password reset links, which have to come via email. But you're expecting those.