They have found one of your passwords, probably by illegally buying up databases when major sites have been hacked (we read about this now and then - Yahoo was one that had a major security breach a while back).
They then send this frightening email out saying they have access and know all your passwords, and all your activity. They don't. All they have is your email address and that one password. Just completely ignore them, delete the email, change all your passwords - especially any sites that used the password they claim to know - and you'll be fine. Also, bear in mind that they are likely to contact you again, possibly repeatedly, when they get no response from you. Just keep ignoring and deleting and they will eventually give up.
Don't worry, gilly, they definitely DO NOT know everything about you and your online activity. This is a well known scam - it's happened to me and to several people I know.