Apple has included a scam prevention feature known as Impersonation Risk Detection in iOS 27, the company said, in order to guard against social engineering scams.
Such scams involve the use of pressure tactics to lead users into disabling the security features on their phone, laptop, or online accounts.
The feature looks for signs that a scam is underway by examining information relating to the device and the Apple Account, then passes on a risk level to the relevant app without sending the original data to that app. It is turned off by default and requires support from app developers.
Apple states that the analysis is carried out on the device itself.
How Apple’s Scam Detection Works and How to Enable It
In a social engineering scam a dishonest person pretends to be an official representative of a bank, a government agency, a technology company such as Apple, Google, or Microsoft, or even a friend, family member or colleague.
They attempt to get users to turn off account security features such as two-factor authentication or to provide their financial information by inventing a fake issue, building up trust, and then pressing the user for a large payment.
Apple states that Impersonation Risk Detection is capable of examining information regarding the iPhone or iPad and the Apple Account in order to look for indications that a scam is underway; once this analysis has been carried out, iOS 27 provides a risk level concerning the app in question. Apple stresses that the app does not get any device or Apple Account data that is used in assessing the risk level.
Then the app determines the next steps to take. A supporting app might insert a delay into each step, display warnings, or request that the user verifies their identity.
The apps can make use of a number of factors in order to decide if a risk assessment is needed, such as major changes to the account, resetting the password, disabling two-factor authentication, or making large payments.
Once an app requests a risk assessment, iOS 27 places the action into one of three risk levels, though Apple does not control what apps do with the information:
- It is unknown whether iOS 27 was able to detect suspicious activity, since Apple states that this does not prove the action to be safe.
- There were some indications of suspicious activity detected.
- There are clear indications of suspicious activity.
The feature is off by default and must be turned on:
- Upgrade to iOS 27 or iPadOS 27 and then open Settings, followed by Privacy & Security.
- Go to the bottom and tap on Impersonation Risk Detection.
- Turn on the toggle that is next to ‘Share with App Developers’ and then tap on ‘Share with App Developers’ in the pop-up window.
When it has been enabled, there is no need to do anything else. If the feature is disabled, it may take as long as 24 hours for the change to take effect, according to Apple, who state this is done in order to protect users against scammers who might pressure them into turning it off.
On the same settings page, ‘Recent Activity’ shows which apps have requested risk levels and the reasons for these requests, and the feature can be turned off for each individual app, again with the possible 24-hour delay.
Impersonation Risk Detection Privacy, Limitations, and Availability
There are two main weaknesses. The first is that it is switched off by default, which means that the majority of people will not make use of it unless they are aware of it.
The second is that it relies on app developers including support for it; while large tech companies and small independent developers might reasonably quickly adopt it, others may not.
Many applications have also already set up their own security systems and might not feel that there is any benefit in providing support for this feature.
In certain areas, banking and payment apps already display full-screen warnings when a payment is made during a phone call or turn off their payment functions if a screen-sharing app is detected. The extent to which the feature is adopted will depend on how the developers respond.
Apple states that the Impersonation Risk Detection carries out its analysis on the device itself and that the data used to produce the risk level stays on the device and does not leave it.
The email, photos, or messages themselves are not examined as part of the evaluation. According to Apple, when an app asks for a risk assessment it is the only information received regarding the kind of action carried out within that particular app, and the apps do not get any further data after the risk level has been generated.
Impersonation Risk Detection is now available on iOS 27 and iPadOS 27, but it is switched off by default and must be activated manually. The extent of its effectiveness relies on the adoption by app developers, although the details of this have not yet been provided. Apple has not released the specific criteria it uses to assign each risk level.
This is concerned with scam prevention; so if anyone thinks they are the target of a scam they should check the urgent request by themselves through the official channels rather than acting under pressure.

