Tech Snips

Apple's iOS 27 Can Now Spot a Scam While It's Happening

Apple's iOS 27 introduces Impersonation Risk Detection, a real-time scam protection feature. Here's how it works and why it matters, especially for businesses.

3 min read Sep 22, 2026
Share:
Apple's iOS 27 Can Now Spot a Scam While It's Happening
Summarize this article with
Opens in a new tab

Apple has quietly rolled out one of its more useful security features in years. It's called Impersonation Risk Detection, and it's built into iOS 27 and iPadOS 27, which shipped on September 14. Unlike most security tools, this one isn't trying to stop a hacker from breaking in. It's trying to stop you from being tricked into handing something over yourself.

The problem it's solving

Social engineering scams work differently from a typical hack. An attacker poses as a bank, a government agency or someone you trust, then pressures or guides you into making a payment or changing your account details. Because you're the one taking the action, tools like two-factor authentication don't help. You've been fooled, not broken into.

How it actually works

Impersonation Risk Detection analyzes signals on your device, things like interaction patterns, timing and context, entirely on the device itself. When you take a risky action in a supported app, like making a payment or changing a password, the app can request a risk assessment. Apple returns one of three levels: unknown, medium or high. Crucially, the app only gets the risk level, not the underlying data used to generate it.

From there, it's up to the app. It might show a warning, add a delay, or ask you to verify your identity before letting the action go through.

The catch: it's off by default

Despite how useful it sounds, the feature doesn't turn itself on. Users need to go to Settings, then Privacy & Security, then Impersonation Risk Detection, and switch on "Share with App Developers." It also only works with apps that specifically support it, so its usefulness will grow as more developers adopt it. Apple also flags a good rule of thumb: be suspicious of anyone who contacts you and tells you to turn the feature off.

Why this matters beyond personal phones

For businesses, this is a reminder that social engineering remains one of the hardest problems in security, precisely because it targets people, not systems. A feature like this won't stop every scam, but it points to where meaningful progress is being made: catching the moment someone is being manipulated, not just the moment a system is breached.

It's also a nudge for any business handling payments, account changes or sensitive data through an app: supporting tools like this isn't just a nice-to-have anymore. It's becoming part of what responsible product security looks like.

The takeaway

Impersonation Risk Detection won't get much fanfare, but it targets a genuinely hard problem: the moment a person, not a system, gets fooled. Whether you're protecting your own accounts or building a product that handles sensitive user actions, it's worth paying attention to.

Frequently asked questions

Q1:What is Impersonation Risk Detection?
A security feature in iOS 27 and iPadOS 27 that analyzes device signals in real time to detect signs of an active social engineering scam.

Q2:Is it turned on by default?
No. Users need to enable it manually through Settings, Privacy & Security, Impersonation Risk Detection.

Q3:Does it work in every app?
No, only in apps that specifically support the feature.


Ready to Scale Your Remote Team?

Workfall connects you with pre-vetted engineering talent in 48 hours.

Related Articles

Stay in the loop

Get the latest insights and stories delivered to your inbox weekly.