When a phone rings, most people answer without suspicion. That reflexive trust is exactly what four hacking groups are exploiting to infiltrate some of the most prominent financial institutions in the United States, according to new research from Google's security team. The attackers aren't deploying cutting-edge exploits; they're simply calling employees and pretending to be someone they're not. Main Developments Google's researchers published a report on Thursday detailing how these groups, which the company tracks under the names Falcon, Helix, Pink, and Redact, are breaching large financial and investment firms. The technique is straightforward: hackers call employees' personal cellphones, pose as co-workers or IT helpdesk staff, and steer targets toward spoofed websites where they enter credentials and multi-factor authentication codes. Cybersecurity professionals call this approach voice phishing, or vishing. Despite the rise of AI-powered autonomous attacks, this old-school social engineering still delivers results, according to the report. The company did not name specific victims, but Reuters reported that leading private equity firms including Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moodys, and TPG are among those targeted. Read also: LightSpy targets 13 countries with new data-wiping capabilities Some of these groups operate public websites that threaten to leak stolen data unless victims pay a ransom. One such site reads: "We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement." The message continues, urging victims to "respond promptly and in good faith." Background Google's researchers believe these four groups may actually operate under a larger umbrella collective the company tracks as UNC6671. Whether they are affiliates, splinter groups, or simply share the same Phishing-as-a-Service infrastructure remains unclear. The report suggests the arrangement likely reflects "a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout." These attackers are not newcomers to the extortion game. Google noted they have previously targeted large companies in manufacturing, real estate, healthcare, insurance, tech, transportation, and hospitality sectors. Their goal in those cases was stealing "valuable intellectual property, software source code, or sensitive VIP client data." The recent pivot toward legal and financial organizations, particularly private equity firms, marks a notable shift in focus. Why It Matters The financial stakes are substantial. Google said one cryptocurrency wallet associated with one of the groups received roughly $10 million in bitcoin during the first few months of this year. Individual ransom demands typically range from $750,000 to $3 million per victim, making these operations highly lucrative even if only a fraction of targets pay. Concentrating on private equity firms appears deliberate. "Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands," wrote Google's researchers. Firms handling sensitive deal negotiations and client wealth are uniquely vulnerable to reputational damage from leaked data. The human element remains the weakest link in corporate security. No matter how sophisticated defensive technology becomes, a convincing phone call can bypass it entirely. These attacks underscore that employee training and verification protocols are just as critical as firewalls and endpoint detection. What's Next CME Group spokesperson Laurie Bischel declined to comment on the report. Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, KKR, Moodys, and TPG did not respond to requests for comment when reached by TechCrunch. Google's researchers continue to monitor UNC6671 and its affiliated brands. The key open question is whether these groups will expand beyond financial services or whether increased awareness of vishing tactics will force them to evolve their methods. For now, employees at major firms would be wise to treat unexpected IT calls with the same skepticism they would apply to suspicious emails.