Apple iOS 27 Introduces Impersonation Risk Detection to Combat Scams
Apple's latest mobile operating systems, iOS 27 and iPadOS 27, feature a new 'Impersonation Risk Detection' tool designed to help apps identify and mitigate social engineering scams.

Apple has rolled out a significant new security feature with its iOS 27 and iPadOS 27 updates, dubbed Impersonation Risk Detection. This innovative tool empowers supported applications to analyze user actions for indicators of active social engineering scams, aiming to protect individuals from being coerced into harmful decisions.
The core problem this feature addresses is the limitation of traditional security measures like two-factor authentication when users are tricked or pressured into taking actions themselves. Attackers often impersonate trusted entities, such as banks or government agencies, to manipulate users into making payments or altering account details. Impersonation Risk Detection seeks to identify these high-pressure scenarios before irreversible damage occurs.
To leverage this protection, users must explicitly opt in. Once enabled, supported apps can request a risk assessment related to specific user actions. The system analyzes various on-device data points, including device usage patterns, communication frequency (calls and emails), and Apple Account information such as app downloads and content purchases. This comprehensive analysis helps build a picture of potential coercion.
Apple emphasizes that the sensitive data used for this assessment, including Photos, Messages, and Mail content, is processed entirely on the device and is not accessed or analyzed by Apple itself. The requesting app receives only a risk level – 'unknown,' 'medium,' or 'high' – rather than the raw data. This privacy-preserving approach ensures that user data remains confidential while still providing valuable security insights.
When an app receives a risk signal, it is up to the application developer to determine the appropriate response. Potential actions include prompting the user for additional identity verification, implementing a mandatory waiting period before a sensitive transaction can proceed, or displaying a clear warning to the user about the potential risks. This allows for context-specific interventions.
The feature is designed to assess risk during critical actions such as making payments, changing passwords, or modifying other sensitive account-security information. The risk levels provide a gradient of concern: 'unknown' indicates no detected suspicious activity, 'medium' suggests some signs of concern, and 'high' signifies significant indicators of a potential scam.
Users can manage Impersonation Risk Detection through the Settings app under Privacy & Security. Here, they can choose to enable or disable sharing risk signals with app developers and review the recent activity of apps that have requested an assessment. This granular control allows users to tailor the feature to their comfort level and specific app usage.
This proactive approach to combating social engineering represents a significant step forward in mobile security, moving beyond reactive measures to anticipate and intercept manipulative tactics before they can succeed. By integrating risk assessment directly into the user experience, Apple aims to create a safer digital environment for its users.