iOS 27 Impersonation Risk Detection: How Apple’s anti-scam setting works

iOS 27 iPadOS 27
Image: Apple iOS 27

Impersonation Risk Detection, available starting with iOS 27 and iPadOS 27, lets a supporting app ask your device for a scam risk level before you send a payment or change your password. The switch is in Settings > Privacy & Security > Impersonation Risk Detection, where it is labeled Share with App Developers.

Apple iPhone 18 Pro 2up
Two iPhone 18 Pro models, front and back. Image: Apple

Apple published its support document on September 14, the day both updates were released. The feature works “only in apps that support it,” and Apple’s iPhone User Guide specifies third-party apps, so the setting does nothing until an app you use adopts it.

The scam it is built to catch

Apple aims it at active social engineering scams, where an attacker “might pose as a bank, government agency, or someone you trust to pressure or guide you into making a payment or changing your account details.” Apple says two-factor authentication can’t always detect this kind of fraud, “because you’re taking the action, even though you’ve been tricked or pressured.”

Don’t miss the best of The Mac Observer

Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.

Or get it by email

When you take a risky action in a supported app, the app can request a risk assessment. Apple analyzes “interaction patterns, timing, context, and basic sensor data” on the device and returns a single risk level. The app decides what happens next. Apple’s examples: it might ask you to verify your identity, add a delay, or show a warning.

The iPad lineup: iPad, iPad Air, iPad Pro and iPad mini side by side.

What the three risk levels mean

  • Unknown: “No evidence of suspicious activity was detected.” Apple adds that this “doesn’t mean that the action was confirmed as safe.”
  • Medium: “Some signs of suspicious activity were detected.”
  • High: “Significant signs of suspicious activity were detected.”

Unknown is the absence of an alarm, not a green light. And since Apple “doesn’t determine or control the action that the app takes,” two apps can respond to the same level differently.

How to turn on Impersonation Risk Detection

  1. Open the Settings app on your iPhone or iPad.
  2. Tap Privacy & Security, then scroll down and tap Impersonation Risk Detection.
  3. Turn on Share with App Developers.

You might need to sign in to the App Store with your Apple Account before the switch turns on. Apple doesn’t say whether it starts on or off, so check the screen yourself, including on a new iPhone 18 Pro.

Why changes can take 24 hours

The delay is deliberate. Apple’s support page says: “If someone directs you to turn this feature off, you might be the victim of a scam. To help protect you, changes to this setting might take up to 24 hours to take effect.”

A caller rushing you through a transfer is counting on you acting within minutes, and switching the protection off may not take effect for up to a day. If anyone, by phone or message, tells you to open this setting, end the conversation and contact the company yourself through a number or app you already trust. Apple’s general scam guidance says that if you’re suspicious about an unexpected message, call or request for personal information, “it’s safer to presume that it’s a scam.” Apple also says it never asks for your Apple Account password or verification codes to provide support.

See which apps have asked, and switch one off

The same settings screen keeps a record. Recent Activity lists the apps that have requested a risk assessment, and Reasons for Access shows the actions that prompted each request. To cut off one app, tap it and turn off its toggle. Per-app changes can also take up to 24 hours. Apple hasn’t named participating apps, so Recent Activity is where you find out whether one of yours has adopted the feature.

What Apple and the apps see

Apple says the information is analyzed on-device, so it “never receives the data used to generate the risk level,” and it “never analyzes the content of your Photos, Messages, or Mail.” Apps receive only the risk level, not the information behind it.

Apple does learn “the type of action you attempted in the app” when an app requests an assessment, such as a payment or a password change.