Impersonation FAQ detection, iOS 27 FAQ’s
Impersonation Risk Detection FAQ (iOS 27 / iPadOS 27)
A practical FAQ for the hidden anti-scam setting Apple added in iOS 27 and iPadOS 27. It is off by default.
Basics
What is Impersonation Risk Detection?
A system-level signal that helps supported apps spot an active social-engineering scam while you are using them—especially when someone is pretending to be a bank, government agency, tech support, or a person you trust, and walking you into a payment or account change.
It exists because classic protections (password, Face ID, 2FA) often still “work” during these scams. You are the one tapping Pay or Change Password. The system is trying to notice that the context looks like coercion or impersonation, not that a stranger stole your login.
Is this the same as spam filtering, Mail warnings, or “Suspicious Message”?
No. Those look at incoming messages and numbers. Impersonation Risk Detection kicks in inside an app, at the moment you try a sensitive action.
Which devices and software?
  • iOS 27 or iPadOS 27
  • Typical supported hardware: iPhone 11 and later, iPhone SE (2nd generation) and later, plus iPads that run iPadOS 27
If the setting is missing, you are probably not on 27 yet.
Is it on by default?
No. You must opt in because supported apps receive a risk level about the action you are attempting.
How it works
What happens when I try something sensitive?
A participating app can request a risk assessment. The phone analyzes on-device signals about your Apple Account and device (patterns, timing, context, basic sensor data), then returns one of three labels to the app:
Level
Meaning
What it does not mean
Unknown
No suspicious signs detected
The action is guaranteed safe
Medium
Some suspicious signs
The app must block you
High
Significant signs of a possible scam
Apple froze the transaction
The app decides the next step: warning, extra verification, delay, or nothing extra.
What kinds of actions can trigger it?
Typical examples Apple and coverage mention:
  • Making a payment or transferring money
  • Changing a password or other critical security details
  • Sharing account information
The exact trigger list is up to each app.
Does Apple read my texts, photos, or email?
Apple says no. It does not analyze content in Mail, Messages, or Photos for this feature. The app receives only the risk level, not the data used to generate it. Apple does learn that an app requested an assessment and the type of action involved.
Does iOS automatically stop the payment?
No. This is a signal to the app, not a hard lock from Apple. If the app is poorly implemented, a High score might still go through after a warning.
Which apps support it?
Only apps that built in Apple’s API. Apple has not published a public roster. Banking, payments, and account-security apps are the obvious candidates. Check the Impersonation Risk Detection screen in Settings for apps that have requested an assessment.
How to turn it on
Exact steps
  1. Open Settings
  2. Tap Privacy & Security
  3. Tap Impersonation Risk Detection
  4. Turn on Share with App Developers
  5. Wait up to 24 hours for it to apply
You may need to be signed in to the App Store with your Apple Account.
How do I see which apps used it?
Same Settings screen. It can show which apps asked for a risk assessment and which actions triggered the request. You can revoke access per app.
Can I leave the master switch on but block one app?
Yes. Use the per-app controls on that same screen.
I flipped the switch and nothing happened.
Common reasons:
  • Still inside the 24-hour activation window
  • The app you are using does not support the feature
  • You expected Apple to pop a system-wide banner; the warning lives in the app, if the developer coded one
Privacy and tradeoffs
Why is the toggle named “Share with App Developers”?
Because the participating app gets a risk label (Unknown / Medium / High) about the action in progress. Apple designed it as opt-in for that reason.
What does Apple itself learn?
That a supported app requested an assessment and the category of action. Not the underlying signals used to score you, and not your message/photo/mail contents (per Apple).
Should I turn this on?
Usually yes if you use banking, shopping, government, crypto, or account apps on the phone and you (or family) get voice/text “urgent account” pressure.
Turn it on with eyes open:
  • It is not a scam-proof shield
  • It only helps in apps that implement it
  • “Unknown” is not a safety certificate
  • A determined victim can still tap through a warning
Does this replace calling the bank back on a known number?
No. If someone claiming to be the bank is on the phone, hang up and call the number on the card or official site. This feature is an extra brake, not a substitute for that habit.
Scams this is meant to catch
What is the attack pattern?
Someone impersonates a trusted institution or person and guides you through an action that looks legitimate on the device:
  • “Your account is compromised—move funds to this safe account”
  • “Verify your identity by changing your password now”
  • “Apple / IRS / Amazon support needs you to send a code or payment”
  • Grandparent / “family emergency” pressure to pay immediately
2FA and Face ID often succeed here because you authorized the step.
Will it catch every phishing site or fake text?
No. It is not a general phishing filter. It is a last-moment context check inside a supported app.
What if I get Medium or High and I know the action is real?
Follow the app’s extra verification. If you initiated the action yourself from a known-good session, it may still score Unknown or Medium depending on timing and other signals. When in doubt, stop and use a second channel (official app support, known phone number).
Troubleshooting
I don’t see Impersonation Risk Detection in Settings
  • Confirm Settings → General → About → iOS Version is 27 or later
  • Update: Settings → General → Software Update
  • On iPad, look under iPadOS 27 Privacy & Security
  • Supervised / MDM devices may hide or lock privacy settings
It’s on, but my bank app never warns me
The bank app may not support the API yet. The feature cannot inject itself into unsupported apps.
Can I test it?
There is no official “demo scam” button. You will only see activity after a supported app requests an assessment.
Does it work on Mac?
Coverage and Apple’s pages for this feature are iOS 27 / iPadOS 27. Don’t assume the same toggle exists on macOS unless Apple documents it there.
Related habits that still matter more
  1. Never move money because a caller or texter told you to.
  2. Hang up and redial the number printed on the card or official website.
  3. Treat “do it now or the account closes” as a scam signal.
  4. Keep Stolen Device Protection and a strong Apple Account recovery setup enabled.
  5. Use unique passwords / passkeys and ignore unexpected password-reset prompts.
One-line summary
Opt-in iOS 27 setting that gives supported apps a privacy-limited “this looks like an impersonation scam” score before payments or account changes; it does not auto-block transactions and it is not on until you enable Share with App Developers.
0
0 comments
Greg Doig
2
Impersonation FAQ detection, iOS 27 FAQ’s
powered by
Tech Brewed
skool.com/tech-brewed-7970
Subscribers and followers to @techbrewednews on X,@techbrewed on YouTube and invited guests
Build your own community
Bring people together around your passion and get paid.
Powered by