Here's a new form of cryptoblackmail. A friend received this out of the blue. Presumably, it's getting sent to everyone on the haveibeenpwnd list.
HIBP doesn't give the password; must have an actual dump. Pretty good for a scare tactic, likely to work against some non-technical people. (Browser exploit to RDP? Probably not. Tracking pixel to a Gmail account? Nope.)
Be careful out there, never pay, never negotiate.
Source - Tweet from @el33th4xor