British Gas has contacted around 2,200 of its customers to warn them that their email addresses and passwords have been exposed online.
The company maintains, however, that its own systems were not breached.
The affected accounts have been disabled following the incident.
The company claims that no financial information, such as bank accounts and credit cards, has been exposed, but attackers could use the passwords to view usernames, addresses and past energy bills.
An email sent to affected customers states: “I can assure you that there has been no breach of our secure data storage systems, so none of your payment details, such as your bank account or credit card details, are at risk.
"As expected, we encrypt and store this information in a secure manner."
"From our investigations, we are confident that the information published online does not originate from British Gas."
As the BBC reports, the customer data may have come from a phishing campaign or from attackers who want to see if people whose data was exposed in other breaches have reused their passwords for other services.
The company, however, insists that its customers' data is secure, even though their email addresses and passwords appear online.
If one compares it to the attack on Talk Talk, where four million accounts were compromised, this particular incident is not too far-fetched.
