I believe that's a classic phishing trick. A really smart phishing site will tell you you got your password wrong a couple of times to harvest your password variants, then on the third attempt redirect you to the real site's login page so you can login there, hopefully unaware that you had ever been phishing.