General rule of thumb for me is if I get an email saying my account is compromised, it's bull. If I think there is some chance it might be real I just log in to the account via the normal method (don't use any links they sent me) and change my password.
What I do is right click on the suspicious message and pick "show headers" (or something similar in your email client) and check the server the message originated on. (Here is a tip: Nigerian servers end in " .ng " and Apple servers are not in Malaysia)