Apple adds on-device scam detection to iOS 27 and iPadOS 27
Apple's iOS 27 and iPadOS 27 include Impersonation Risk Detection, an opt-in feature that flags social engineering scams on the device and leaves the response to app developers.
The tool runs entirely on-device, so Apple does not see users' photos, texts or other personal content. When a supported app requests a risk assessment, it receives a label and none of the underlying data behind that determination. The feature is opt-in and is positioned as a complement to other online safety measures rather than a replacement for them.
Impersonation Risk Detection works while a scam is in progress. When a user takes a sensitive action such as making a payment or changing account security details, a supporting app can request a real-time risk assessment. The phone generates that assessment by analyzing interaction patterns, timing, context and basic sensor data, all locally. On that basis the system assigns one of three levels. Unknown means no suspicious activity was detected, which does not make the action safe. Medium means some signs of suspicious activity were found. High means major signs of suspicious activity were detected.
Apple describes the tool as filling a gap left by defenses such as two-factor authentication. An attacker posing as a bank representative or a government official can pressure a user into approving a questionable transaction or sending a password, and artificial intelligence can make such approaches more convincing. The decision on how to respond belongs to the app developer. Depending on the risk level returned, an app might ask the user to verify their identity, impose a short waiting period or display a warning.
Users who want the protection can turn it on in Settings, then Privacy & Security. Scrolling down to Impersonation Risk Detection allows them to toggle on Share with App Developers. The same menu shows which apps have requested a risk assessment and why, and lets users adjust those apps' access.
Apple also advises treating as a red flag any contact from someone who insists the feature be switched off. For that reason, disabling it can take up to 24 hours to take effect. The feature only works with apps built to support it, and Apple has not published a list of those apps yet.
Engadget describes the addition as a logical extension of Apple's privacy-first security work, such as Safari's anti-tracking tools. Social engineering scams do not break through a user's defenses; they convince the user to open the door, a point at which no two-factor code can raise an alarm. The new tool is aimed at that blind spot, which the report says no browser setting or password manager fully addresses.
Editor's Summary
Apple has added Impersonation Risk Detection to iOS 27 and iPadOS 27, an opt-in, on-device feature that flags likely social engineering scams when users make payments or change security settings. It returns one of three risk labels to supporting apps, whose developers decide whether to request verification, add a delay or show a warning. The feature only works with apps that support it, and Apple has not yet published that list.