Phase 3 · Break It

Recon Brief: Marrowfield Community Trust

Everything below is publicly visible on the internet. Nothing here was obtained by breaking into anything. Your job: figure out what an attacker learns from it.

This is the same nonprofit whose network you built this morning

You're helping Marrowfield Community Trust understand their exposure. Read each item. What technology are they running? Who's the easiest person to target? Where's the way in? Then — the real point — decide for each item whether they actually needed it public.

Item 1 — "Our Team" page

Marcus Delacroix-Whitfield — Executive Director
mdelacroix-whitfield@marrowfieldtrust.org

Priya Raghunathan — Director of Operations
praghunathan@marrowfieldtrust.org

Tomas Oyelaran — Program Manager, Youth Services

Bettina Kowalczyk — Office Manager & IT Coordinator

"Bettina joined us in March after twelve years in retail management. She keeps our office — and our computers — running."

Item 2 — Job posting (posted 3 weeks ago)

Part-Time IT Support — Marrowfield Community Trust

Small nonprofit (14 staff) seeks part-time IT help, roughly 10 hrs/week. You'll be supporting:

  • Windows 10 and Windows 11 workstations
  • Microsoft 365 (Business Basic)
  • Our Ubiquiti UniFi network across two sites
  • Remote access via OpenVPN for staff working from home
  • QuickBooks Desktop on a shared server

Experience with donor management software (we use Bloomerang) a plus. No on-call required. Reports to the Office Manager.

Note: our previous IT contractor retired in May and we've been managing on our own since then.

Item 3 — Conference talk abstract

"Doing More With Less: Technology on a Shoestring"
Regional Nonprofit Summit, April 2026
Presented by Bettina Kowalczyk, Marrowfield Community Trust

"When your IT budget is under $5,000 a year, you get creative. I'll walk through how we run a two-site operation on consumer-grade tools, why we still use a shared admin login for our network gear, and how we finally got off spreadsheets for donor tracking."

Item 4 — Press release (last month)

Marrowfield Community Trust Opens Second Location on Delacroix Avenue

"...the new Delacroix Avenue site will house our youth programming and includes a computer lab with twelve donated workstations. Executive Director Marcus Delacroix-Whitfield thanked the Hartwell Foundation for funding the buildout, which includes new networking equipment and security cameras throughout the facility..."

Item 5 — Facebook post (public, 2 weeks ago)

"Big thanks to our summer volunteers! 🎉 Ten students from Marrowfield High spent the week helping us set up the new computer lab. They even got the wifi working — password is on the whiteboard, don't tell anyone 😅"

[Photo: six people in front of a whiteboard. Text on the whiteboard is partially legible.]

Then research the technology — not the organization

Once you've read the footprint, use your browser agent on the real technologies it names. This is legitimate research on public technical information. Point it at products, never at a specific organization you intend to attack — you should be able to say that distinction out loud.

1. "What is OpenVPN, and what are the common misconfigurations that make it a security risk for a small organization?" 2. "Windows 10 reached end of support in October 2025. What does that mean for a small nonprofit still running it?" 3. "What are the standard security recommendations for network cameras on a small business network?"

The defensive turn — this is the point

Go back through all five items. For each one, decide: did Marrowfield actually need this public? Most of it was reasonable — a nonprofit should thank volunteers, recruit staff, publicize a new site, and share what it learned. The failure wasn't publishing. It was the specific operational details that rode along. Security literacy is knowing which sentence to cut, not going silent.