A threat actor operating under the moniker "2019" claimed to distribute an exfiltrated corporate dataset containing approximately 116,000 user records belonging to the Western Australian educational publisher. While the actor alleged exposure of deep personally identifiable information (PII)—including order archives, customer contact lines, and localized payment methods—R.I.C. Publications released an official corporate disclosure clarifying that the security anomaly was restricted entirely to an automated website email relay function with zero systemic infrastructure penetration or client data leakage.