Your iPhone just got a hidden anti-scam upgrade in iOS 27: How to activate it

ZDNET’s key takeaways

  • Apple has unveiled a new security option called Impersonation Risk Detection.
  • Added in iOS 27 and iPadOS 27, this tries to protect you from social engineering scams.
  • Apps that support the feature will warn you of a potential threat.

Social engineering scams are often successful because they bypass traditional security protections to trick you into doing something that puts you at risk. Now Apple has created a new defense to protect iPhone and iPad users from these types of scams: Impersonation Risk Detection

Also: A stranger can learn a lot about you online in 5 minutes – how to check and delete it

Apple introduced the new security feature in iOS 27 and iPadOS 27. If enabled, this option will warn you before you perform certain actions in a supported app that could lead you to become an active cheater. The goal is to help you when more traditional security measures like two-factor authentication fail to detect or protect you from a potential threat.

How impersonation risk detection works

Let’s say you’re using an app on your iPhone or iPad that supports Impersonation Risk Detection. You are about to perform a sensitive action, such as making a payment, changing your password or sharing your account details. Impersonation Risk Detection steps to analyze your Apple account and the information on your device to look for signs of fraud.

Based on the results, Apple assigns one of the following three risk levels to the app:

  • unknown: This means that no suspicious activity has been detected, but it does not confirm that the action you want to take is safe.
  • Medium: This indicates that some signs of suspicious activity have been detected.
  • High: This means that significant signs of suspicious activity have been detected.

The app then decides what to do next. If a high level of suspicious activity is detected, the app may ask you to verify your identification, display a warning, or delay your action before it gets you into trouble. The app makes this determination, not Apple.

Also: I’ve been using my iPhone 18 Pro for a week – these 5 features make the upgrade worth it

Apple will analyze various information with an interaction to generate the risk level, but it never receives the data itself. The company does not analyze your content in such apps as mail, messages and photos. But Apple learns the type of actions you’ve tried when an app asks for a risk rating. Supported apps only get the risk level and not the data used to create them.

Impersonation Risk Detection is turned off by default because a supported app requires a certain level of access to your actions and activities.

How to Enable Impersonation Risk Detection

To enable the setting in iOS 27 or iPadOS 27, go to Settings and select Privacy and Security. Swipe down on the screen and tap the Impersonation Risk Detection setting. On the next screen, turn on the switch for “Share with app developers.” After enabling this setting, you may need to wait 24 hours for it to take effect.

Also: Mobile phishing is a bigger threat than email now – how to stay protected

All apps that participate in Impersonation Risk Detection appear on the same screen, so you can always check them periodically for recent activity. You can see which apps have requested a risk assessment and which actions triggered the request. Here you can also turn off access for individual apps.

Both built-in and third-party apps can support the feature, although Apple doesn’t list specific programs on its support page. However, with social engineering scams so pervasive, hopefully enough apps will jump on this bandwagon to better prevent people from falling victim.

Leave a Comment