Even in the age of AI-powered autonomous cyberattacks, the crude, tried and tested, hacking techniques of tricking victims into doing things they shouldn’t are still producing great results.

Groups of unknown hackers are targeting and breaking into large financial and investment firms in the United States with the goal of stealing sensitive data to extort the victims with the threat of publishing it, Google’s security researchers wrote in a report on Thursday.

The company did not name the victims, but Reuters reported that among them there are leading private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG.

The hacking groups, which Google dubbed Falcon, Helix, Pink, and Redact, are using an old-fashioned technique to break into those firms: phone calls to employees’ personal cellphones in which the hackers pretend to be coworkers or IT helpdesk staffers, during which they try to trick targets into entering their credentials and multi-factor codes on spoofed websites, according to Google. In cybersecurity parlance, this technique is known as voice phishing, or vishing.

Some of the groups identified by Google run websites where they publicize their hacks and threaten to leak the stolen data as a way to extort the victims into paying a ransom, a common strategy among cybercriminals.