
Apple's new iPhone and iPad feature can protect you from impersonation scams
Apple shipped Impersonation Risk Detection with iOS 27 and iPadOS 27. It analyzes device behavior in real time to flag social engineering scams, runs on-device and is opt-in.
Apple introduced a new security feature alongside iOS 27 and iPadOS 27, and it arrived without much fanfare. Called Impersonation Risk Detection, it looks for social engineering scams while they are happening rather than blocking an attack at the perimeter. The feature is opt-in and runs entirely on-device.
What it detects
Two-factor authentication and similar protections assume an attacker is trying to break in. Impersonation Risk Detection targets a different threat: a caller posing as a bank employee, or a text that looks like a fraud alert, both designed to create urgency and persuade the user to open the door themselves. When the user is the one approving the transaction, no verification code can flag the problem.
When someone performs a sensitive action, such as making a payment or changing account security settings, an app built to support the feature can request a real-time risk assessment. The iPhone or iPad generates that assessment locally by analyzing interaction patterns, timing, context and basic sensor data.
Three risk levels
The system returns one of three labels: Unknown, when no suspicious activity was detected (which does not mean the action is safe), Medium, when some signs of suspicious activity were found, and High, when major signs were detected. An app receives only the label, without the underlying data behind the determination.
What happens next is up to the app developer. Depending on the level returned, an app might ask the user to verify their identity, impose a short waiting period or display a warning. The feature only works with apps built for it, and Apple has not published a list of supported apps yet.
How to turn it on
On an iPhone or iPad, open Settings > Privacy & Security, scroll to Impersonation Risk Detection and toggle on Share with App Developers. The same menu shows which apps have requested a risk assessment and why, and lets the user adjust their access.
Apple says that if someone contacts you and insists you turn the feature off, that should be treated as a red flag. For the same reason, switching it off can take up to 24 hours to take effect. Because the analysis stays on the device, Apple never sees photos, texts or other personal content.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.