
This was Day 2 of Smarthub Academy's "Beyond the Click" cybersecurity webinar, held August 2, 2026. Where Day 1 covered the theory of how cyber criminals operate, Day 2 moved into live demonstration — showing attendees exactly how a phishing attack is carried out from start to finish. Justina Augustus opened with the agenda and ground rules, and Emmanuel Uwa recapped the previous session before diving into the main content. He began by defining digital identity — a person's full online presence across email, social media, phone numbers, and photos — and stressed that an email account is the "master key" that can be used to reset passwords and compromise every linked account, potentially leading to financial theft. The centerpiece was a live phishing simulation using a tool called GoFish against a mock target ("Smart Global"). Emmanuel built a fake login page, generated a convincing HTML verification email disguised as an IT service desk request, launched the campaign using a temporary email identity, and captured the submitted credentials in real time. He showed how attackers immediately redirect victims to the legitimate site so the compromise goes unnoticed, and how they later analyze captured data like timestamps, operating system, and browser. He then covered the broader threat landscape: romance scams and market fraud built on stolen identities, the dangers of oversharing daily activities online, and Multi-Factor Authentication as an essential defense layer. Importantly, he explained MFA's limits — tools like Evilginx use man-in-the-middle techniques to steal active session tokens rather than passwords, bypassing MFA entirely. On ethics, Emmanuel declined a request to demonstrate Evilginx live, explaining that advanced exploitation tools are reserved for trained students and that the academy prioritizes ethical, professional responsibility over teaching offensive techniques. The session closed with core best practices — strong unique passwords, MFA, careful URL and link verification, keeping software updated, and above all never clicking a link you're not fully sure about.