Apple added Impersonation Risk Detection in iOS 27 and iPadOS 27 to address a problem that traditional account security does not always stop: a real user being manipulated into making a payment or changing sensitive account information.

The feature is useful, but its name can sound broader than it is. It does not certify that a person, message or payment is safe. It produces a risk level that a supported app can use when the user is about to perform a potentially sensitive action.

What problem is Apple trying to solve?

Social-engineering scams often bypass normal login protections because the victim is already signed in. A scammer may pose as a bank, government agency, employer or family member and pressure the user to send money, reveal information or change account settings. Two-factor authentication cannot always stop that because the account holder is the one approving the action.

How the detection works

According to Apple, a supported app can request a risk assessment when the user is about to do something that could be dangerous during an active scam, such as making a payment or changing critical account information.

The system analyzes information about the device and Apple Account and returns one of three risk levels to the app: Unknown, Medium or High. Apple says the app receives the risk level rather than the underlying information used to calculate it.

What does “Unknown” mean?

This is a crucial detail. Apple's documentation says Unknown means no evidence of suspicious activity was detected. It does not mean the transaction or request has been verified as safe. A convincing scam can still exist without producing the signals the system looks for.

What happens after a Medium or High result?

The app decides what to do. It might show a warning, introduce a delay, request extra identity verification or take another protective step. Apple does not control the final response inside the third-party app.

That also means the experience can differ between banks, payment services and other supported apps. Two apps can receive the same type of risk result and respond differently.

Is it available in every app?

No. Apple states that Impersonation Risk Detection works only in apps that support it. Installing iOS 27 does not automatically add the feature to every banking or payment app on the phone.

Users can find the system setting under Settings → Privacy & Security → Impersonation Risk Detection. Availability inside a particular app still depends on that app's implementation.

What privacy protection does Apple describe?

The key privacy claim is separation between the assessment and the underlying signals. Apple says the supported app receives the risk level, not the device and account information used to produce it. That design reduces the need to expose all of the detection inputs to every app that wants a risk signal.

What the feature cannot replace

  • Recipient verification: Confirm who is actually receiving money before approving a transfer.
  • Independent contact: If someone claims to be your bank, call the official number from the card or app instead of a number they provide.
  • Time: Urgency is a common scam tactic. A warning system works best when the user is willing to stop.
  • Account security: Strong passcodes, device updates and two-factor authentication still matter.
  • App-specific fraud controls: Banks and payment services may have additional warnings and transfer limits that should not be ignored.

Why this matters more than another spam filter

Spam filters try to stop the suspicious message before it reaches you. Impersonation Risk Detection is aimed at a later point in the scam: when the user may already believe the story and is about to carry out an action. That makes it a different layer of defense.

A practical rule for payment scams

If a caller, text or chat tells you to move money immediately to protect it, stop the transaction and contact the institution independently. Do this even if the phone shows no warning. Security features can reduce risk; they cannot make coercive instructions trustworthy.

Bottom line

Impersonation Risk Detection is a useful addition because it recognizes that modern scams target people as much as passwords. Its strongest role is as a second signal at the moment of action. Treat a warning seriously, but never treat the absence of a warning as proof that a payment, caller or account change is legitimate.

Apple's current technical explanation is available in Apple Support: About Impersonation Risk Detection.

More app-security and AI coverage is available in our U.S. technology section.