BREEZE COMET Expands Attacks on Brazil Payments
BREEZE COMET is hitting financial and payments firms in Brazil and running hundreds of fraudulent transactions in 24 to 48 hour bursts.
BREEZE COMET has compromised financial, retail, and e-commerce organizations in Brazil since at least 2024 and, once inside core apps and payment platforms, carried out hundreds of fraudulent transactions in 24 to 48 hour bursts.
Update September 4, 2026: New reports clarify that BREEZE COMET is not limited to attacking financial apps, but is compromising payment infrastructure at banks, fintechs, processors, retailers, exchanges, and banking software providers in Brazil. Its operators have also been confirmed to use legitimate credentials and mTLS material, allowing them to pass Pix cryptographic checks.
BREEZE COMET has compromised financial, retail, and e-commerce organizations in Brazil since at least 2024 and, once inside core applications and payment platforms, carried out hundreds of fraudulent transactions in bursts lasting 24 to 48 hours. The most recent technical reports place the group inside the infrastructure of entities authorized to process payments, with impact on Pix, STR, and boleto, and access to assets worth tens of thousands of dollars in at least one investigated incident.
What are the attackers doing?
The threat actors are combining banking malware, impersonation, and AI-driven automation to target digital channels and payment systems. Google Cloud attributes to BREEZE COMET activity against banks, fintechs, payment operators, merchants, and banking software providers in Brazil, with a focus on fraudulent transfers through Pix, STR, and boleto.
The technical reporting is consistent in showing that the group is not focusing on individual banking victims. Instead, it is infiltrating the infrastructure of entities authorized to process payments. SecurityLab, Valor Econômico, and GBHackers described attacks on banks, fintechs, processors, retailers, exchanges, and banking software providers tied to Brazil’s payments ecosystem.
Valor reported that, after gaining access to financial institution networks in Brazil, the group uses reconnaissance tools and custom malware to identify credentials and move into payment systems. It also uses generative language models to speed up the creation of scripts for network reconnaissance, credential validation, tool deployment, victim selection, and data extraction.
An independent analysis of Pix added that operations attributed to BREEZE COMET pass all of the system’s cryptographic checks because they use mTLS material and valid credentials from authorized entities. That approach shifts the risk away from the protocol and toward identity security and integration channels.
NEXSIGHT CYBER WIRE also described BREEZE COMET abusing persistent identity accounts and access to RSFN, the Rede do Sistema Financeiro Nacional, together with reusable mTLS credentials, to execute fraudulent transfers that bypass standard anti-fraud controls at Brazilian banks.
Media outlets and cybersecurity blogs added that, in at least one of the incidents investigated by Google, the group obtained assets valued at tens of thousands of dollars, with two waves of hundreds of transfers in less than 48 hours once it reached transactional systems.
TecMundo, citing Zimperium, added that in Latin America banking malware groups with AI capabilities are abusing mobile accessibility features. According to that warning, they can silently read the screen, approve transfers in the background, bypass biometric controls, and intercept codes sent through messages and notifications.
How are banks and fintechs responding?
Financial institutions are adding more real-time validation layers to decide whether a transaction is legitimate without creating friction for users. Valor explained that banks in Brazil are strengthening the use of transaction data, device information, and behavioral biometrics to combat Pix payment fraud.
In the Dominican Republic, Visa said its Visa Advanced Authorization solution analyzes up to 400 unique attributes in real time during transaction authorization. The company said the system combines artificial intelligence, authentication, biometrics, and passkey-style credentials to detect potentially fraudulent activity.
Also in Brazil, banks and mobile operators are cross-referencing transaction behavior with mobile network signals through the Open Gateway initiative. According to Real Nacional, they use APIs to silently verify whether the device and SIM match the line’s history, detect recent SIM or device changes associated with fraud, and reduce the need for extra codes for trusted customers.
Colombia Fintech reported that Ionix Latam deployed its Ionix Verify platform, which analyzes identity documents, performs biometric comparisons, and adds other security layers. In Chile, G5 Noticias said financial institutions are also strengthening defenses with advanced biometrics, end-to-end encryption, and deep learning algorithms capable of distinguishing a real human user from a synthetic impersonation generated with AI in real time.
How widespread is fraud in the region?
Fraud attempts remain widespread and persistent across several Latin American countries. Bloomberg Línea reported, citing an Experian survey, that between 68% and 74% of respondents in Colombia, Mexico, Chile, Peru, and Panama received at least one fraud attempt in the past year.
That same coverage later explained that Experian is combining advanced analytics, identity-based risk models, and AI tools to validate in real time who is behind an action in digital channels. The goal is to verify authorizations and the legitimacy of transactions in those same markets.
Latin Times, citing data from Finnovista and BioCatch, added that digital identity theft cases in Latin America rose 84% between 2024 and early 2026. In Mexico, BioCatch recorded a 324% increase in account takeover attempts against digital banking customers during that period, nearly twice the rate seen in Colombia.
In Chile, a local outlet reported that payment fraud reached about $98 million in the first half of 2026. That coverage said financial institutions are reinforcing their defenses with advanced biometrics, end-to-end encryption, and deep learning to distinguish real users from synthetic impersonations.
What identity fraud techniques are being used?
Traditional eKYC controls are losing effectiveness against fake identities that are becoming cheaper and more convincing. Mexico Business warned that synthetic documents, AI-generated faces, voice cloning, and deepfakes are eroding remote identity verification in digital banking, account opening, and access to financial services.
Meganoticias and Duplos Chile described a banking scam based on the RUT. First, criminals lock the account using national ID data, then they pressure the victim into giving up the verification code received by SMS or email, under the pretext of fixing the problem. With that code, they reset passwords and take control of the account.
AJN1, for its part, said AI tools for voice and image cloning are directly increasing biometric fraud and data theft in Brazil. That analysis noted that LGPD classifies facial and voice biometrics as sensitive data, and that Pix fraud victims should activate the Special Refund Mechanism immediately to try to block the funds.
What are security and risk firms saying?
Cybersecurity and fraud companies are calling for more real-time monitoring and stronger authentication controls. Zimperium recommended that banks strengthen the internal architecture of their apps against unauthorized modifications and deploy real-time detection of anomalous behavior during transactions.
Iupana reported on the reaction of Latin American CISOs after a public warning from technology companies led by OpenAI. According to that coverage, security leaders are reassessing risk models, tightening authentication controls, and increasing monitoring for impersonation attempts and synthetic identity generation in digital banking channels.
Bloomberg Línea also noted that the use of AI in fraud pushed Experian to support its checks with advanced analytics, identity models, and real-time validation. The result is a shift in defense, moving from account-opening controls to reviewing the legitimacy of each action in digital channels.
Sources
- Breeze Comet and Pix: how fraud passes every cryptographic checkpk-sharma.com· PK Sharma
- The Hacker Diaries — Case File No. 014theitguysfix.com· The IT Guys Fix
- Grupo hacker mira sistemas de pagamentos no Brasil e usa IA para acelerar ataques, mostra Googlevalor.globo.com· Valor Econômico
- La IA gana espacio en la prevención del fraude en pagos digitaleseldinero.com.do· El Dinero
- ラテンアメリカにおける不正検知・防止市場の規模、シェア、動向、成長および2026~2034年の予測note.com· Market Insights
- Fraud, Deepfakes, and the Collapse of eKYC as a Line of Defensemexicobusiness.news· Mexico Business
- Malware com inteligência artificial mira aplicativos de banco na América Latinatecmundo.com.br· TecMundo
- IA reforça defesa dos bancos no combate à fraudevalor.globo.com· Valor Econômico
- AI Deepfake Scams Are Draining the Remittances Latino Families Send Home — Here's How to Fight Backlatintimes.com· Latin Times
- Ionix Latam despliega en la región nueva plataforma para prevenir fraudes de identidadcolombiafintech.co· Colombia Fintech
- Troca de chip acende alerta de fraude para bancos e operadoras que cruzam dados do celularrealnacional.ai· Real Nacional
- Financially Motivated Threat Actor BREEZE COMET Targets Brazilcloud.google.com· Google Cloud Blog
- Lo utilizan para bloquear tu cuenta y robar tu accesoduplos.cl· Duplos Chile
- "Lo utilizan para poder enviar estafas": Así funciona la nueva estafa bancaria que parte con el RUTmeganoticias.cl· Meganoticias
- Golpes com IA: como a legislação e o mercado respondem às fraudes biométricasajn1.com.br· AJN1
- Los fraudes y estafas con IA más recurrentes en México, Colombia, Chile, Perú y Panamábloomberglinea.com· Bloomberg Línea
- OpenAI alerta sobre ciberataques de IA: así reaccionan los CISO de América Latinaiupana.com· Iupana
- Financially Motivated Threat Actor BREEZE COMET Targets Brazilcloud.google.com· Google Cloud
- Google раскрыла группу BREEZE COMET, которая два года охотится на платежные системы Pix, STR и Boletosecuritylab.ru· SecurityLab
- Grupo hacker mira sistemas de pagamentos no Brasil e usa IA para acelerar ataques, mostra Googlevalor.globo.com· Valor Econômico
- Financially Motivated Threat Actor BREEZE COMET Targets Brazildaily.dev· daily.dev
- Breeze Comet: KI-gestützte Angriffe auf Pix- und STR-Infrastruktur in Brasilienit-boltwise.de· IT Boltwise
- ブラジルの金融インフラを狙う『BREEZE COMET』 — GTIGとMandiantが決済乗っ取りの手口と生成AI悪用を報告cyber.nexsight.co· NEXSIGHT CYBER WIRE
- BREEZE COMET attacca il sistema finanziario brasilianomatricedigitale.it· Matrice Digitale
- Los fraudes y estafas con IA más recurrentes en México, Colombia, Chile, Perú y Panamábloomberglinea.com· Bloomberg Línea
- Hackers Breach Brazilian Financial Firms and Execute Hundreds of Fraudulent Transactionsgbhackers.com· GBHackers
- BREEZE COMET Targets Brazilian Financial Networks for Fraudulent Transfers | Mallorymallory.ai· Mallory
- ¿Cómo la IA está blindando el dinero de los chilenos frente al fraude?g5noticias.cl· G5 Noticias



