This New IOS 27 Feature Can Help Protect You From Fraud.

Starting with iOS 27 , your iPhone now has a built-in anti-fraud feature designed to protect against social engineering scams. These schemes rely on pressure tactics to trick you into bypassing the security features of your phone, laptop, or online accounts. Here’s how Impersonation Risk Detection works in iOS 27, what it can do, and its current limitations.
How the impersonation risk detection system works to protect you from fraud
In a social engineering scam, the attacker impersonates an official representative of a bank , government agency, or technology company like Apple , Google, or Microsoft. The scammer may even impersonate trusted friends, family members, or colleagues. They will try to trick you into disabling account security measures like two-factor authentication or coax you into sharing your financial information. They will create a fictitious problem, gain your trust, and then pressure you into making large payments.
Apple states that the Impersonation Risk Detection feature can analyze information about your iPhone or iPad and your Apple account to check for signs of active fraud. Once the analysis is complete, iOS 27 will report the risk level to the app that has been targeted. Apple emphasizes that the app does not receive any data associated with your device or Apple account that was used to assess the risk level.
Further steps depend on the app. If the app supports identity risk detection, it can add a delay to each step, display warnings, or even request identity verification. Starting with iOS 27, apps can use various factors to determine the need for a risk assessment, including significant account changes, password resets, disabling two-factor authentication, making large payments, and more.
What are the risk levels in the impersonation detection system?
Once an app requests a risk assessment from iOS 27, the operating system can analyze the action and classify it into one of three risk levels (again, Apple doesn’t control what apps do with the risk level information):
-
Unknown : This means iOS 27 wasn’t able to detect any suspicious activity. Apple states that this doesn’t mean the action was confirmed as safe.
-
Medium Risk Level : This risk level is assigned when iOS 27 detects signs of suspicious activity.
-
High Risk: This risk level is associated with significant signs of suspicious activity.
How to enable impersonation risk detection
After updating your iPhone to iOS 27 (or iPad to iPadOS 27), go to Settings > Privacy & Security , scroll down, and tap “Impersonation Risk Detection .” Turn on the toggle next to “Share with App Developers.” Now tap “Share with App Developers ” in the pop-up window. Once Impersonation Risk Detection is enabled, you don’t need to take any further action. Please note that if you try to disable this feature, it may take up to 24 hours for the changes to take effect. This is to protect against scammers who may pressure you to disable this feature.
On the same settings page, you can see which apps have requested access to your risk levels and why. This information will be displayed in the “Recent Activity” section. You can also disable this feature for individual apps that appear in this section, but again, disabling this setting may take up to 24 hours.
Limitations of Impersonation Risk Detection Methods
The strength of security features is determined by their weak points. In the case of the identity spoofing detection feature in iOS 27, there are two major weak points. First, the feature is disabled by default. Most users won’t delve into settings to accidentally discover it, and the feature won’t be widely used if no one knows about it. Second, the feature also relies on app developers adding it. Large tech companies and independent developers may implement it fairly quickly, but other developers may be slow to implement it.
It’s also worth considering that many apps have already invested significant resources into building their own security infrastructure and may not see the point in adding support for this feature. In India, all banking and payment apps display multiple full-screen warnings when you attempt to make a payment during a phone call. Some apps may even disable payment features if they detect that you have a screen-sharing app installed on your device. So, ultimately, it will all depend on how app developers respond to this feature.
Does the impersonation risk detection system keep my data private?
Apple states that its identity spoofing risk detection feature performs analysis on-device, and the data used to determine the risk level never leaves your device. The company also emphasizes that the content of your email, photos, or messages is not analyzed during the risk assessment. When an app requests a risk assessment, Apple states that it only receives information about the type of activity you performed within that specific app. After determining the risk level, apps do not receive any additional data about you.