$ techbeacon▋
Darkweb

Brazilian Firms Hit by Breeze Comet Fraud Scheme Targeting Payment Networks

Brazilian Firms Hit by Breeze Comet Fraud Scheme Targeting Payment Networks

Brazilian financial institutions, retailers and e‑commerce platforms are confronting a wave of fraudulent activity traced to a threat group now identified as Breeze Comet, formerly known as UNC5669. Security analysts say the actors have generated hundreds of illicit transactions through the country's domestic payment infrastructure since early 2024, prompting a coordinated response from banks, merchants and cyber‑security firms.

Google Threat Intelligence Group and Mandiant, the cybersecurity firms that first detailed the campaign, describe Breeze Comet as a financially motivated actor that leverages automated tools to exploit weaknesses in Brazil's payment processing ecosystem. The group appears to have shifted from earlier, less sophisticated operations to a more systematic approach that targets multiple sectors simultaneously.

According to the investigators, the fraudsters employ scripted requests that mimic legitimate purchase flows, allowing them to slip past standard fraud‑prevention checks. By exploiting the interoperability of local card‑issuing networks and payment gateways, the actors can initiate transactions that appear authentic, making detection challenging for organizations that rely on conventional rule‑based filters.

The influx of counterfeit purchases has forced affected companies to suspend certain payment channels, incur charge‑back fees and allocate additional resources to forensic analysis. While precise loss figures have not been disclosed, industry sources note that the volume of fraudulent attempts has strained existing anti‑fraud measures and prompted a rapid reassessment of transaction monitoring protocols.

Brazil has become a focal point for cyber‑crime groups seeking to capitalize on the region's growing digital commerce market. Experts point to a broader trend of organized actors targeting emerging economies where payment infrastructures are expanding faster than security controls. Collaborative efforts between local banks, payment processors and international threat‑intel teams are now viewed as essential to curtail the group's activities.

Both Google Threat Intelligence Group and Mandiant continue to track Breeze Comet's tactics, urging organizations to adopt multi‑factor authentication, real‑time analytics and shared threat‑intel feeds. As the investigation proceeds, authorities anticipate that further disclosures will illuminate the full scope of the operation and guide additional defensive measures across the Brazilian digital economy.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related