That's the thing, you don't know if it's their staff. If I was IRCC, I would send an email AND try to contact you over the phone as well.
If I was a person with a malicious intent, once I get your information, I could have easily done the same thing. What I cannot easily do is to send an email with CIC letterhead from CIC email domain.
It is highly likely to be a prank, a very very cruel prank.
Also, did you online status reverted back to In Process from Decision Made?
I heard that several people with actual background check concern had this happen to them.