They typically get the passwords from hacking into some obscure sites passwords. Since most people use the sameish password everywhere, they can email people (like you) and you will think they actually have a pertinent pw. They don't have your pw to everything, although they could be trying to...