It is a bluff. Do not pay
These messages follow a fixed script: the sender claims to have installed something on your device, to have watched you through the camera, and to have copied your contacts. They demand payment in cryptocurrency within a short deadline, and they warn you not to reply or tell anyone.
The password is the only part that is real, and it is not evidence of anything. It is included because it is the one detail that makes a mass-mailed template feel personally addressed to you.
The countdown and the instruction not to tell anyone are there for the same reason: to stop you doing the one thing that would settle it, which is looking into it calmly or asking someone else.
Where the password came from
It came from a data breach at some service you once signed up for, not from your computer. When a website is breached, the account list is traded and eventually published, and those lists are combined into enormous collections of address-and-password pairs. Whoever sent this simply bought one and mail-merged it into a template.
Two details usually confirm this. The password is old - often something you stopped using years ago. And it is a password you used on one specific site rather than your main email password, which points at that site's breach rather than at your device.
Many of these messages also appear to come from your own email address, offered as proof that the sender controls your account. They do not. Sender addresses can be forged trivially unless the domain publishes and enforces email authentication, which is exactly what DMARC exists to do. Seeing your own address in the From field is evidence of spoofing, not of access - and you can confirm it by checking whether the message actually appears in your Sent folder. It will not.
What to do
- Do not pay and do not reply. Paying marks you as someone who pays, and the demands continue.
- Change that password anywhere it is still in use. This is the only genuinely urgent step, because the pair is circulating and will be tried against other services automatically.
- Stop reusing it. A password manager makes this practical rather than aspirational.
- Turn on two-factor authentication on your email account first, then on banking and anything holding payment details.
- Check your address in a reputable breach-notification service to see which site leaked it, and treat any other account using that password as exposed.
- Cover the camera if it makes you feel better. It is not the actual risk here, but there is no harm in it.
- Keep the message rather than deleting it immediately, in case you decide to report it.
If you have already paid, stop any further payments, keep the transaction details, and report it - cryptocurrency payments are rarely recoverable, but the report matters. If the message reached a work address, tell your IT team; they will want to know which credentials of yours are circulating.
Where a password of yours has genuinely been entered into a fake page rather than merely leaked in a breach, the steps are different and more urgent - see I clicked a phishing link.