Google links generative-AI tooling to BREEZE COMET financial intrusions in Brazil
Google Threat Intelligence and Mandiant reported compromises of Brazilian organizations in which BREEZE COMET used large language models to support reconnaissance, credential validation, deployment, victim-specific pivoting and data extraction.
- First observed
- Sep 1, 2026, 12:00:03 PM
- Disclosed
- Sep 1, 2026, 12:00:03 PM
- Status
- Monitoring
- Confidence
- 94%
- Organization
- BREEZE COMET, Mandiant, Google Threat Intelligence Group
- Last reviewed
- Sep 4, 2026
Observed
Facts supported by sources
- Mandiant reported investigating compromises of Brazilian financial, retail and ecommerce organizations attributed to BREEZE COMET.
- Recovered tooling and scripts indicated use of generative AI and large language models to support reconnaissance, credential validation, mass deployment, victim-specific pivoting and data extraction.
- The report described hundreds of fraudulent transactions across two waves and at least one theft worth tens of thousands of US dollars. Because individual event dates were not disclosed, this record uses the disclosure date as its timeline anchor.
Assessment
Interpretation, not observation
- The source supports AI-assisted malware development and operations, not autonomous criminal action.
- The campaign was described as active and developing at publication time.
Impact
Impact
Financial theft, credential compromise, malware deployment and data extraction affecting organizations in Brazil.
Response
Response
Google and Mandiant published technical indicators, detection guidance and hardening recommendations. Responses by the individual affected organizations were not disclosed.