Breeze Comet Group Executes Hundreds of Fraudulent Transactions Across Brazilian Financial Sector
AI-generated from multiple sources. Verify before acting on this reporting.
SAO PAULO — A financially motivated cybercriminal group identified as Breeze Comet, formerly known by the alias UNC5669, executed hundreds of fraudulent transactions targeting financial services, retail, and e-commerce organizations across Brazil. The coordinated campaign utilized custom malware, compromised user accounts, and direct manipulation of payment systems to siphon funds from victim institutions.
The attack wave was detected on Sept. 1, 2026, marking a significant escalation in the group's operational capabilities within the Latin American market. Breeze Comet has shifted tactics from opportunistic breaches to highly targeted intrusions designed to bypass standard security controls in Brazil's digital economy. The group's activities disrupted payment processing for several major retailers and financial intermediaries, forcing temporary suspensions of online transaction services as investigators assessed the scope of the intrusion.
Security experts attribute the successful execution of these transactions to a combination of sophisticated malware tailored specifically for Brazilian banking protocols and the exploitation of stolen credentials. By infiltrating internal networks, the actors gained access to administrative tools used to authorize and route payments. This allowed them to manipulate transaction logs and move funds through multiple layers before detection mechanisms could trigger alerts.
The financial services sector in Brazil has faced increasing pressure from cybercriminals seeking to exploit the region's rapid digital transformation. Breeze Comet's operations highlight a growing trend where threat actors invest heavily in custom tools to target specific payment infrastructures rather than relying on widely available exploits. The group's rebranding from UNC5669 suggests an evolution in their organizational structure and operational focus, though the core methodology remains centered on direct financial theft.
Brazilian authorities and affected organizations are currently working to contain the breach and recover lost funds. Several financial institutions have initiated emergency protocols to freeze suspicious accounts and reset authentication credentials for compromised systems. The scale of the fraudulent transactions indicates that the group maintained persistent access to victim networks for an extended period before the initial discovery on Sept. 1.
Questions remain regarding the total financial impact of the campaign, as many transactions were routed through complex chains of shell accounts and cryptocurrency exchanges. Investigators are also examining whether Breeze Comet coordinated with other criminal entities to launder the proceeds or if the group operated independently. The full extent of the data exfiltration accompanying the financial theft has not yet been determined, leaving uncertainty about potential long-term risks for consumer privacy.
As recovery efforts continue, the incident underscores the vulnerability of Brazil's interconnected digital payment ecosystem to advanced, financially driven threats. Regulatory bodies are expected to review current security mandates in light of the attack, while organizations face immediate pressure to fortify defenses against similar custom malware campaigns.