I was just going to post that these are real legit emails and to tell you to get on to your apple ID and change your password and remove all changed info, but looks like you have found out already.
you say you are not impressed with the notification process, how? it's not like apple can physically call you, all they can really do is send an email when account info is changed,
and you can tell that the website iforgot.apple.com is a legit apple site from the address,
if you had have acted quicker (on the first email) you would have got into your account and headed off the illegitimate purchases before they happened.