web account password compromised

I received an email from a stranger presenting one of the old passwords that I used. Although the password was correct, I no longer use that password for any of my important website such as bank or social media, for at least 5 -6 years. The email threatens me that if I do not pay a certain sum of money through BitCoin, they will expose my other personal information online. I am wondering how legit is this threat and what action should I take?

Thank you.

JC