Breeze Comet: Financially Motivated Hackers Target Brazilian Payment Systems
Researchers at Google Threat Intelligence Group (GTIG) and Mandiant have identified a financially motivated threat actor, tracked as Breeze Comet (formerly UNC5669), that has been targeting Brazilian financial services, retail, and e-commerce organisations since 2024. According to the researchers, the group specialises in manipulating payment systems and banking software to conduct fraudulent transfers, with hundreds of unauthorised transactions attributed to its activity.
While the report focuses on Brazil-specific targeting, the tactics used to compromise payment infrastructure highlight a broader risk facing any business that relies on digital banking, point-of-sale systems, or third-party payment processors. Attackers who gain a foothold in these systems can often move funds or alter transaction data before defenders notice anything unusual, making early detection and strong access controls essential.
Australian small businesses that operate in retail, e-commerce, or rely on international payment processors should treat this as a reminder to review how their payment and banking software is secured, particularly around third-party integrations and remote access.