Hello,
This is the famous Pegasus phishing scam. If you Google about it, you will find tons of information about this. Bottom line - your account is safe, your computer is safe. Nothing is hacked. No need to change password.
They are using scare tactic and ID spoofing to make you believe that your account is compromised, so that they can blackmail you into doing what they asked you to do.
Email spoofing happens when someone uses an outside mail server to send messages that pretend to come from your email address by forging the "From" field. They do not have access to your actual email account. To prevent and detect this, email providers like Microsoft use protections like SPF (to define which servers are allowed to send on your behalf), DKIM (to attach a digital signature to prove the email is real), and DMARC (to tell other servers what to do if a message fails these checks). If a spoofed email fails these checks, it will usually be flagged as spam or rejected.
So, if the email is already in spam/junk folder, you have nothing to worry about. You can just ignore it.