I got an email today starting with: "I know one of your passwords is <insert password> whilst visiting some website, etc.
the mentioned password is accurate!
He then goes on with some incorrect details:
When you were watching video clips, your web browser started out working as a Remote control Desktop with a key logger which provided me accessibility to your screen and also webcam. after that, my software collected every one of your contacts from your Messenger, Facebook, as well as e-mail. after that i created a video.
Now I dont have a webcam, nor do I have FB Messenger on my PC, no any contacts stored on the email that he addressed me to.
He's demanded $1,600 through bitcoin else he will apparently release a video showing me watching some explicit content on webcam.
Again, dont have a webcam, nor have i visited any explicit on my desktop pc..
How is it possibly he has an accurate (unique) pw to me, yet rest of the information seems to be a try-hard general which doesnt apply.
What can he do with this data?
Should I reply and troll him?
First question: do you use the same e-mail and password combination on any other sites?
Odds are that the database of one of the websites was "hacked", leaked, or just plain stolen by an employee and then sold off.
That database may have stored your password in plaintext or a weak cipher and was cracked.
Basically if all they've got is your username and password - then hop to it - change one of those details. Everywhere you use that combination. Either change your e-mail address. Or change your password. Because you know the combination is no longer safe.