Threat Intelligence

Breeze Comet: Financially Motivated Hackers Target Brazilian Payment Systems

The Hacker News · 2 Sept 2026
Key Takeaway Regularly review and restrict access to payment and banking systems, and monitor transaction logs for unusual activity, especially if you use third-party payment processors.

Researchers at Google Threat Intelligence Group (GTIG) and Mandiant have identified a financially motivated threat actor, tracked as Breeze Comet (formerly UNC5669), that has been targeting Brazilian financial services, retail, and e-commerce organisations since 2024. According to the researchers, the group specialises in manipulating payment systems and banking software to conduct fraudulent transfers, with hundreds of unauthorised transactions attributed to its activity.

While the report focuses on Brazil-specific targeting, the tactics used to compromise payment infrastructure highlight a broader risk facing any business that relies on digital banking, point-of-sale systems, or third-party payment processors. Attackers who gain a foothold in these systems can often move funds or alter transaction data before defenders notice anything unusual, making early detection and strong access controls essential.

Australian small businesses that operate in retail, e-commerce, or rely on international payment processors should treat this as a reminder to review how their payment and banking software is secured, particularly around third-party integrations and remote access.

payment fraud Brazil financial cybercrime

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.