Apple's iOS 27 Adds Scam Detector To Spot When You're Being Manipulated
Impersonation Risk Detection analyses on-device behaviour during sensitive actions

Apple has added a new security feature to iOS 27 and iPadOS 27 designed to detect signs that a user may be caught in an active social engineering scam. Called Impersonation Risk Detection, the feature is designed for situations where traditional protections such as two-factor authentication and password managers cannot help because the user is being persuaded or pressured into taking an action themselves.
The feature is disabled by default and must be enabled by the user. Apple says it can take up to 24 hours to become fully active. The analysis is performed entirely on the device. Apple says it does not read private content from Photos, Messages or Mail, while apps do not receive the underlying sensor or behavioural data. Instead, developers receive a risk classification.
Apps Can Request a Real-Time Scam Assessment
When a user attempts a sensitive action in a participating app, such as making a high-value payment, transferring money or changing account security settings, the app can request a risk assessment from the system.
Apple says the assessment examines interaction patterns, timing, context and basic sensor information on the device. It can also consider broader usage signals, including call and email volumes and activity on the user's Apple Account.
The assessment returns one of three categories: 'Unknown,' 'Medium' or 'High.'
'Unknown' means the system detected no suspicious activity, although Apple says this does not mean an action is necessarily safe. 'Medium' indicates some signs of suspicious behaviour, while 'High' indicates significant signs that the user may be under manipulation or facing suspicious activity.
Apple leaves the response to individual app developers. Depending on the result, an app could request additional identity checks, delay a transaction or show a warning to the user.
Apple Keeps the Underlying Behavioural Data Private
Developers are not given the underlying data used to generate the assessment. They receive only the risk level. Apple says this approach is intended to limit privacy risks and prevent apps from gaining access to detailed information about how users interact with their devices.
The system relies on higher-level signals, such as approximate call and email volumes and Apple Account activity. These can be assessed alongside unusual actions, including a sudden payment or change to security settings.
Protection Is Opt-in and Takes Time To Switch Off
Users can enable Impersonation Risk Detection through Settings > Privacy & Security > Impersonation Risk Detection by switching on 'Share with App Developers.' Apple has also built a delay into the feature when users attempt to disable it. Turning off the protection, or revoking access for a particular app, can also take up to 24 hours.
The delay is intended to make it harder for a scammer to pressure someone into immediately disabling the feature before completing a transaction. Apple says that anyone directing a user to turn off the feature could indicate a scam.
iOS 27 also adds several smaller upgrades, including AI-powered password fixes, new Lock Screen tools and separate alarm volume controls. The Action Button can trigger multiple features, while FaceTime gains Dual Camera and a safety filter. Siri and Apple Wallet also get updates, alongside new call and messaging controls.
© Copyright IBTimes 2026. All rights reserved.

