So you got one of those spam emails that said "we took control of your webcam while you were watching porn and if you don't pay up we'll release the video ... to prove we know it was you, here's your password ..."
How do they know your password?
Well, when you register for a site (or an app) they have a database containing all the usernames, email addresses and passwords somewhere. I the site/app is well-built then the passwords are encrypted1 and if they are not, then the developer should be forbidden from ever releasing code again. A database with unencrypted passwords is a danger to everyone, as we will see.
Ultimately, everyone is going to get hacked one day - you can put locks on your doors and windows, but you'll still probably get burgled one day. The thieves will try and grab the user database and will then try to "brute force" the passwords. To do this they run through a dictionary and try all the words in there, to see if, when encrypted, they match the entry in the database2.
Once they've figured out what the passwords are, they then release those email addresses and password combinations to other criminals - who can then try those same combinations on other sites.
That's exactly why you should always use a different password for every site and every app, which in turn is why password managers like 1Password and LastPass are so important.
But that's also what this porn spammer has done - they've found your email address in one of these databases, then sent you an email using your password to try and persuade you that they have genuine footage of you.
They can send this email out to millions of people and it only takes one of them to pay up for the spammer to get rich. So it's a scam that really works.
––––––––––––––––––––––––––––––––
1 Technically, it's not encryption, but a process called "hashing and salting" - encryption is reversible, but hashing and salting is one-way
2 Again, a bit of a simplification - they use a thing called a "rainbow table" to match known words with their hashed versions.