How iOS 27's New Impersonation Risk Detection Aims to Stop Scammers
Apple's iOS 27 introduces a new anti-scam feature called Impersonation Risk Detection, allowing apps to check device context for fraudulent activity.

Apple has officially released iOS 27, bringing a wave of significant security improvements compared to previous versions. Among the new additions is a unique anti-scam feature called Impersonation Risk Detection, designed to tackle a threat area Apple has rarely explored before.
The feature is specifically built to catch users in the middle of sophisticated scams, such as threat actors posing as bank fraud departments and manipulating victims into moving money or resetting passwords. These are complex situations where traditional security tools like Face ID or two-factor authentication provide limited help.
Within a supported app, when performing critical actions like sending a payment or changing a password, the application can request an assessment from the iPhone. iOS 27 analyzes interaction patterns, timing, context, and basic sensor data to determine if the behavior is legitimate, while strictly avoiding personal content in Photos, Messages, or Mail.
Upon completion, the app receives a simple risk level: Unknown, Medium, or High. Apple deliberately leaves the enforcement to app developers rather than freezing transactions automatically, allowing apps to trigger identity verification or delays as they see fit.
A major critique of the feature is that it is tucked away behind a toggle in settings and disabled by default, meaning users who actually need it might never enable it. However, Apple implemented a robust 24-hour security delay before the feature can be turned off, mirroring the logic behind Stolen Device Protection.



