British Gas has contacted about 2,200 of its customers to warn them that their email addresses and account passwords were posted online.
It says, however, that it does not think its own systems were breached.
The affected accounts have been disabled following the discovery.
No bank account or payment card details would have been revealed, but the logins could have been used to view users' names, addresses and past energy bills.
An email sent to affected customers states: "I can assure you there has been no breach of our secure data storage systems, so none of your payment data, such as bank account or credit card details, have been at risk.
http://www.bbc.co.uk/news/technology-34663210