Skip to content
Tech News
← Back to articles

Security Bite: iOS 27 now lets apps ask your iPhone if you’re being scammed

read original more articles
Why This Matters

Apple's iOS 27 introduces Impersonation Risk Detection, a system-level tool that lets supported apps query the iPhone for signals indicating a user may be actively falling for a scam, such as unusual account changes or money transfers. This matters because it addresses a growing threat—social engineering scams—that traditional security tools like Face ID and two-factor authentication can't prevent, potentially protecting millions of users from financial fraud.

Key Takeaways

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.

Last week, Apple officially released iOS 27 to everyone. The update comes with many new security features, which is nice given how lackluster iOS 26 was in that area. However, there’s one new anti-scam feature in particular that targets an area Apple has never explored before and could eventually be massively beneficial to users. The feature is called Impersonation Risk Detection.

All in all, it’s meant to catch users in the middle of a scam.

Impersonation Risk Detection in iOS 27 Settings. 9to5Mac

There are many different scenarios in which this feature could be triggered, but one of the more likely ones is a threat actor posing as a bank’s fraud department and walking a user through moving money into a “safe account” or resetting their password. Types of situations where security features like Face ID and two-factor authentication aren’t much help.

When in a supported app (it’s unclear which apps offer support yet, but I doubt it’s many), and you do something like send a payment or change your account password, the app can now ask your iPhone for a read on the situation. iOS 27 will then look at previous interaction patterns, timing, context, and even basic sensor data to determine whether the actions taken are legitimate.

According to Apple, Impersonation Risk Detection doesn’t look at content in Photos, Messages, or Mail for context. The feature doesn’t look at the point of intrusion. And the only thing an app receives is a single word: “Unknown,” “Medium,” or “High.” Unknown means nothing was tripped, which Apple is careful to note is not confirming you’re safe.

Now, it’s important to note that if there is a Medium or High flag, iOS doesn’t freeze the money transfer or block the password change. It doesn’t even throw up a system alert. Apple hands the app the risk level and leaves it to the app developer to determine what to do next. This could be making the user verify their identity again or adding some kind of delay before a user is able to change critical settings.

Apple also says it doesn’t control or determine what an app does with the flag, so one app might treat a Medium risk level differently than another.

Users can also keep tabs on this feature in settings under recent activity. It shows which apps have requested a risk assessment and what action triggered it. Users can revoke access per app from there as well.

... continue reading