Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization
Threat Actor Meta
Summary
Hide ▲
Show ▼
Researchers have profiled Breeze Comet as a Brazil-based e-crime group with overlapping aliases and a monetization model centered on fraudulent transfers. The cluster's activity links it to Brazilian financial services, retail, and e-commerce targets, widening exposure across payment and banking workflows. Its operating model combines payment-system abuse, banking-software manipulation, and access to internal transaction environments, raising direct financial-loss risk. Alias overlap across UNC5669, Plump Spider, and SHADOW-AETHER-064 strengthens cross-vendor attribution and ecosystem tracking.
Related Happenings
Breeze Comet Brazilian payment-system fraud campaign
Campaign
H score32
First: 01.09.2026 20:19
Last: 01.09.2026 20:19
Sources 1
How related:
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024.
About this happening:
Breeze Comet has been conducting a financial intrusion campaign against Brazilian financial services, retail, and e-commerce organizations since 2024, putting paym...
Breeze Comet Brazilian payment-system fraud campaign
CampaignHow related: Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024.
About this happening: Breeze Comet has been conducting a financial intrusion campaign against Brazilian financial services, retail, and e-commerce organizations since 2024, putting paym...
Scattered Lapsus Shiny Hunters' harassment-driven extortion operating model
Threat Actor Meta
H score33
First: 02.02.2026 18:15
Last: 02.02.2026 18:15
Sources 1
About this happening:
Scattered Lapsus Shiny Hunters (SLSH) is now using a harassment-driven extortion model that pairs stolen data with swatting, threats, and publicity pressure, raising the s...
Scattered Lapsus Shiny Hunters' harassment-driven extortion operating model
Threat Actor MetaAbout this happening: Scattered Lapsus Shiny Hunters (SLSH) is now using a harassment-driven extortion model that pairs stolen data with swatting, threats, and publicity pressure, raising the s...
Timeline
-
01.09.2026 20:19 2 articles · 3h ago
Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization
Initial DisclosureThe cluster was identified as a Brazil-based e-crime group with activity dating back to September 2023 and a fraud-first monetization model. Alias overlap across vendor tracking tied the actor to a broader financial-crime ecosystem.
Show sources
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems — thehackernews.com — 01.09.2026 20:19
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems — thehackernews.com — 01.09.2026 20:19