Earlier quoted context omitted.
It's very normal for password reset pages to say something to the effect of "if this email address is registered with us, you will receive an email..." and they can could also add something like "you can also try create an account here". Instead they opted for the option where every time a "hacker" is trying to use the form to compromise an account, it spams the victim with this email. As most of the world is not Nor…
I still see no problem with this implementation. If someone is trying to compromise or even locate accounts tied to your email, wouldn't you want to know?
What course of action could be taken when you get an email like this indicating a "hacker" is trying their luck to see if your email address has an account on BestBuy.com even though you don't have an account there (and probably never will)?
I've had my email address for 16 years, lots of "hackers" are aware of it due to account list leaks from various services I have used over that time and there is an entire industry which tries to compromise accounts from these lists.
If I got notified of every automated script's failed attempt to do something malicious involving my email address, I would probably get several notifications a week, possibly per day, all of which are probably unactionable.
So to answer your question, no, I most definitely wouldn't want to know about someone trying see if my email address was used for an account on some random website I'll never use.
On the the other hand, if a password of mine was being used by a "hacker", that I would want to know about.