Groups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report.

Even in the age of AI-powered autonomous cyberattacks, the crude, tried and tested, hacking techniques of tricking victims into doing things they shouldn’t are still producing great results. Groups of unknown hackers are targeting and breaking into large financial and investment firms in the United States with the goal of stealing sensitive data to extort the victims with the threat of publishing it, Google’s security researchers wrote in a report on Thursday. The company did not name the victims, but Reuters reported that among them there are leading private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. The hacking groups, which Google dubbed Falcon, Helix, Pink, and Redact, are using an old-fashioned technique to break into those firms: phone calls to employees’ personal cellphones in which the hackers pretend to be coworkers or IT helpdesk staffers, during which they try to trick targets into entering their credentials and multi-factor codes on spoofed websites, according to Google. In cybersecurity parlance, this technique is known as voice phishing, or vishing. Some of the groups identified by Google run websites where they publicize their hacks and threaten to leak the stolen data as a way to extort the victims into paying a ransom, a common strategy among cybercriminals. “We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement,” read one of the sites. “Respond promptly and in good faith, and the matter is resolved without further incident.” Google researchers said that the different groups may all be part of a larger umbrella collective the company tracks under the name UNC6671. But it’s unclear if they are affiliates, splinter groups, or they all use the same Phishing-as-a-Service infrastructure. “We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout,” read the report.