Apple has introduced Impersonation Risk Detection with iOS 27 and iPadOS 27. The feature lets supported apps request a risk assessment when a user takes an action that could be tied to an active social engineering scam, such as making a payment or changing account details. Apple notes that attackers often pose as banks, government agencies, or trusted contacts, and that traditional security measures like two-factor authentication cannot always catch these cases because the user is knowingly taking the action under pressure.

The assessment runs on-device. Apple says it may consider device-use patterns, including the approximate number of calls and emails sent or received, along with Apple Account information such as app downloads and purchases. It may also factor in interaction patterns, timing, context, and basic sensor data. Apple says it does not analyze the contents of Photos, Messages, or Mail, and the requesting app receives only the resulting risk level, not the underlying information. Apple itself does not receive the underlying device data, although it learns what type of action triggered the request.

The system returns one of three ratings: unknown, medium, or high. An unknown rating means no evidence of suspicious activity was detected, but it is not a confirmation that the action is safe. The requesting app decides how to respond, and it may ask the user to verify their identity, impose a waiting period, or show a warning. Users can manage the feature under Settings > Privacy & Security > Impersonation Risk Detection, review which apps have requested assessments under Recent Activity, and revoke access for individual apps.