Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Executive Summary
Breeze Comet (formerly UNC5669) is a financially motivated threat actor that has targeted Brazilian financial services, retail, and e‑commerce organizations since 2024. According to Google Threat Intelligence Group and Mandiant, the group specializes in manipulating payment systems and banking software in Brazil to execute fraudulent transfers. The actor has carried out hundreds of illicit transactions through compromised payment platforms.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-01T17:19:24+00:00 - Category: threat-intel
Original Description: Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers." The adversary
"Life is not measured by the breaths you take, but by its breathtaking moments."
— Michael Vance