To be proactive, learn about phishing, scams, and Apple practices, etc., see:
If you see apple.com/bill, itunes.com/bill, or an unfamiliar charge on your statement https://support.apple.com/en-us/HT201382
Identify legitimate emails from the App Store or iTunes Store https://support.apple.com/en-us/HT201679
How to avoid scams when using Apple Pay to send and receive money https://support.apple.com/en-us/HT208226
This scam related information from Apple including reporting scams to Apple see Avoid phishing
emails, fake 'virus' alerts, phony support calls, and other scams https://support.apple.com/en-us/HT204759
How to identify scams related to purported apple notifications—per Eric Root.
“Apple will always address you by your name or the name they have on file for you, not Dear Customer, Dear Client or by using your e-mail address. The e-mail will be from @apple.com or @iTunes.com. E-mail addresses can be spoofed. You can go to Mail/View/Message/Show all Headers to see more. Apple emails won't have poor grammar/misspellings. Apple e-mails will never contain an attachment. Apple will never request personal information by email such as Social Security numbers, your Mother’s maiden name or full credit card numbers. …The only exception to the above I have noticed is if you order something from the Apple Store (apple.com), your receipt will be addressed to Dear Apple Customer. That is a receipt for a purchase you initiated.”