As others have posted here, this particular email is a known scam. Sad, isn't it, that there are people who view breaching the web of trust between people that is all that makes it possible for us to function at any level beyond "every man for himself" as nothing more than a business model?
This one is a scam, and so are many others similar to it. That said, however, there are people who do this kind of thing "for real.: Most often, they are aiming at businesses - healthcare organizations are a particular favorite - and most often, they notify victims not by email, but by popping up a screen after encrypting all their files. But I imagine that private individuals occasionally get hit, too.
Here are a few things you can do for your "peace of mind":
(1) Use good "Password hygiene." Do not re-use passwords, either between websites or repeatedly on the same website. It's a pain having a lot of passwords to remember, but using a good password manager program takes the pain out of that. Use STRONG passwords (a password manager can generate them for you). Change them periodically - I try to do this every three months or so.
(2) If it is available, enable 2-factor authentication on your email, and for that matter, anywhere else you log in - your bank, amazon.com, etc. This means that when you log in, a message will be sent to your phone, giving you a one-time numeric code you must also enter to log in. This way, even if a hacker gets your password, they can't get into your account without that code that goes to YOUR phone not theirs. 2-factor authentication isn't perfect - there are ways to defeat it - but hackers are generally looking for the "easy targets," and using it makes you a less easy target.
(3) If you're using Microsoft outlook, you can check the history of successful logins by clicking on the little round avatar of your account in the upper-right corner; then clicking "my microsoft account"; then clicking "security"; then clicking "see your sign-in activity." All of your log-ins should be recorded here, with the town or city from which you logged in and a notation of "successful" or "unsuccessful." Look for any locations you don't recognize, and make sure that they are "unsuccessful." I will say that it's a little unsettling to see that there actually ARE attempts to log into my account from places like Russia, China, Indonesia, and occasionally from other cities here in the United States! But it's reassuring to see that they are unsuccessful. I will note, however, that you can't entirely trust the locations that are reported, since hackers can sometimes hide their locations by hacking into a distant computer and then trying to log into your account from that, or by attempting to do their dirty work through a VPN or proxy server.
(4) Reporting the attempted extortion attempt to the FCC and/or the IC3, of course, doesn't help...but don't hold your breath. While those groups would surely be pleased if they could put a stop to this sort of crime, the criminals are almost certainly located in a country which turns a blind eye to such shenanigans, as long as the criminals do not attack computers located in that country.