Google has a slew of resources to determine if an email is phishing. some of the info i found tells you how to check who the email is coming from, not the name that appears in the "from" box..
It_is_NOT_legit. I've seen it twice before with emails from a law firm. It is a short attack, plain and simple. They tell you they are investigating, then ask you how many shares you have if they scared you. The wording is almost exactly the same. FAKE