Brazil hit by 'Breeze Comet' crew draining bank accounts through payment software
Google's Mandiant team says the group has quietly siphoned money from Brazilian banks, retailers and e-commerce firms since 2024 by hijacking the software that moves payments around.

Key points
- Google Threat Intelligence Group and Mandiant have named a financially motivated crew called Breeze Comet, previously tracked as UNC5669, active against Brazilian targets since 2024.
- The group targets banks, retailers and e-commerce companies in Brazil, focusing on the internal software that authorises payments.
- Investigators say the attackers have run hundreds of fraudulent transfers through Brazilian payment systems.
- The crew is described as specialising in manipulating banking software rather than classic ransomware or data theft.
- Victims are concentrated in Brazil, but the playbook, tampering with payment plumbing from the inside, is one other regions should study.
A hacking crew that Google now calls Breeze Comet has spent the better part of two years quietly stealing money from Brazilian companies by tampering with the software they use to move payments.
Google Threat Intelligence Group and its Mandiant investigators laid out the activity this week, saying the same group was previously tracked under the placeholder name UNC5669. They describe Breeze Comet as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers." The reporting was picked up by The Hacker News.
In plain terms: the attackers do not just break in and grab files. They get inside the systems that authorise and send payments, then push money out as if a real employee had clicked the button.
Who is being hit?
Brazilian banks, retailers and e-commerce firms. Google's team says the group has been active since 2024 and has run hundreds of fraudulent transactions through Brazilian payment rails, which is the behind-the-scenes network that shuffles money between businesses and banks.
That matters because the target is not the customer's phone or laptop. It is the company's own back office. Once the attackers are in there, the fraud looks legitimate to the bank on the other end.
How does the attack actually work?
Breeze Comet goes after payment and banking applications that Brazilian businesses run internally. Instead of stealing card numbers or planting ransomware, which is malicious software that locks files until a payment is made, the crew tampers with the workflow that sends money out.
Think of it like this. A retailer's finance team uses a piece of software to approve supplier payments. The attackers quietly change what that software does, so a transfer that looks routine on the screen actually sends funds to an account they control.
In practice, this is a much harder fraud to spot than a phishing email, where criminals send fake messages to trick staff into handing over passwords. The transactions come from the right computer, the right user account, at the right time of day.
What we know at a glance
| Detail | What Google/Mandiant say |
|---|---|
| Group name | Breeze Comet (previously UNC5669) |
| First seen | 2024 |
| Region | Brazil |
| Sectors | Financial services, retail, e-commerce |
| Method | Manipulating payment and banking software to send fraudulent transfers |
| Scale | Hundreds of fraudulent transactions |
Should ordinary customers be worried?
Not directly, but keep an eye on statements. The fraud sits inside businesses, not on shoppers' devices, so there is nothing to patch on your phone. If you bank in Brazil or buy from Brazilian merchants, the usual sensible habits apply: check your statements, turn on transaction alerts, and query anything you do not recognise quickly, because chargeback windows are short.
Businesses in the region have more to do. The failure mode here is trusting the payment application as a black box. If nobody is watching what that software actually sends, a small change to its behaviour can bleed money for months.
Why is Google talking about it now?
Because the group has been quiet by design. Financially motivated crews that hide inside payment software tend to avoid the noisy tactics that trigger headlines. Naming Breeze Comet and linking it back to the older UNC5669 activity gives defenders in Brazil, and the vendors who sell them banking software, a shared label to hunt for.
One thing the post-mortem will say: the money moved through legitimate channels, using legitimate credentials, from legitimate machines. That is the whole point.
Operational takeaway: if you cannot see what your payment software is doing at the network and process level, you are trusting it on faith.



