The Australian Centre for the Moving Image fell victim to a SQL database exfiltration. Threat actor "2019" posted a clean user repository containing visitor login credentials, full names, email addresses, and subscription histories.