iOS 27 Adds Impersonation Risk Detection to iPhone, but It Ships Switched Off
Apple's iOS 27 introduces Impersonation Risk Detection, a feature that flags active social-engineering scams to supported apps and is disabled by default. Users must switch it on in Settings.
Apple describes the tool as protection against active social-engineering scams, the kind in which an attacker poses as a bank, a government agency or someone the user trusts in order to pressure or guide that person into making a payment or changing account details. Such scams are difficult for conventional defenses to catch. Two-factor authentication and similar measures cannot always detect them, Apple says, because the user is the one carrying out the action, even though the action was taken under pressure or deception. Scams of this type commonly arrive through text messages, emails or phone calls, and the built-in call and message screening already available in iOS cannot stop a fraud from succeeding if the user decides to act on it.
According to Apple's description, Impersonation Risk Detection analyzes information about the user's device and Apple Account to look for signs that a scam is underway, and then returns a risk level to the app. The app receives only that risk level, not the underlying information used to generate it, and the app itself decides what to do next. Possible responses include asking the user to verify their identity, adding a delay, or displaying a warning.
The risk level handed to apps falls into one of three categories. Unknown means no evidence of suspicious activity was detected. Medium means some signs of suspicious activity were found. High means significant signs of suspicious activity were detected. Once an app has the level, it determines its own course of action, which may include prompting for additional authentication or showing a message warning about scams.
Enabling the feature is done in the Settings app on an iPhone running iOS 27. The user opens Settings, goes to Privacy & Security, selects Impersonation Risk Detection, and turns on the option labeled Share with App Developers.
Apple has not published a list of the apps that support the feature, and Impersonation Risk Detection works only inside apps that have adopted it. That means a user who switches the setting on will not necessarily see any change in apps that have not implemented it.
The default-off arrangement places Impersonation Risk Detection alongside other privacy and security controls that Apple leaves to the user to activate, even as the company promotes the tool as a defense against fraud that existing safeguards handle poorly. No figures have been released on how many apps have adopted it or how often it has flagged suspicious activity since iOS 27 shipped.