Google has warned that cybercriminal groups are using voice phishing attacks to breach some of the largest financial and investment firms in an effort to steal sensitive corporate data for extortion.

In a threat intelligence report released on Thursday, Google said the attackers rely on social engineering rather than sophisticated malware, calling employees on their personal mobile phones while impersonating colleagues or IT support staff.

The attackers then direct victims to fake websites where they are tricked into entering corporate login credentials and multi-factor authentication codes.

Google tracks the groups under the names Falcon, Helix, Pink and Redact, although researchers believe they may all belong to a broader threat cluster known as UNC6671.

According to Reuters, organisations targeted in the campaign include Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s and TPG.

Google said several of the groups operate leak websites where they publish details of cyberattacks and threaten to release stolen information unless victims pay a ransom.

“We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honour an agreement,” one of the extortion sites stated.

The researchers said it remains unclear whether the groups operate independently, function as affiliates or share the same phishing-as-a-service infrastructure.

“We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands, possibly in an effort to compartmentalise operations, hide overall breach volumes, and isolate any negotiation fallout,” the report said.

Google noted that the threat actors have previously targeted companies in manufacturing, healthcare, insurance, technology, transportation, hospitality and real estate before shifting their attention to legal and financial institutions.

According to the report, firms involved in mergers and acquisitions, capital deployment and litigation have become particularly attractive targets because they possess highly valuable confidential information that can increase the pressure to pay ransoms.

Google also revealed that one cryptocurrency wallet linked to the group received about $10 million in Bitcoin during the first few months of the year, while ransom demands typically range from $750,000 to $3 million.

Several of the companies named in the report declined to comment or did not immediately respond to requests for comment.

Bank Recapitalization-abacha-university-ad