Security1 publisher2 min readPublished
Apple's iOS 27 gives opted-in apps an on-device scam risk level to flag possible impersonation
Impersonation Risk Detection in iOS 27 returns one of three risk levels to an app when a customer makes a payment or changes account security settings, and the scoring runs on the device only after the customer switches it on.
The Watch · Security desk

What happened
- Apple has shipped a scam-prevention feature called Impersonation Risk Detection with iOS 27 and iPadOS 27, letting supported apps request a risk assessment during a user action tied to an active social engineering scam.
- The app decides the response, choosing between identity verification, a waiting period and an on-screen warning, and it receives only the level rather than the data behind it.
- Customers must turn on Share with App Developers under Settings > Privacy & Security before any app can receive the signal, and may have to sign in to the App Store with an Apple Account.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability A fraud team can act on call and email volumes and purchase history that it has no way to collect itself, while receiving only a three-level verdict.
- constraint The signal works in one direction only: medium and high can justify friction, and unknown cannot justify releasing a payment faster, because Apple says it does not confirm safety.
- decision Each integrating bank owns what a high rating does to a transfer, and the liability that attaches to a warning the customer clicked through.
- constraint Enrollment cannot be part of an inbound fraud call, since a toggle change may need 24 hours before any app sees the difference.
The scam this aims at is the authorized payment. Someone calls claiming to be the bank's fraud desk, the customer moves the money themselves, and every control that checks identity sees the right person on the right device. Apple wrote: "Traditional security measures like two-factor authentication can't always detect this kind of scam. That's because you're taking the action, even though you've been tricked or pressured." [3]
An app can ask for an assessment when the customer makes a payment, changes a password, or modifies other critical account-security information [9]. It gets back one of three levels [10]. The scoring runs on the device [6]. The app sees the level and nothing underneath it [7]. Apple says it does not receive the device data behind the level, though it does learn the type of action the user attempted when the request came in [7].
Two of the three answers tell a fraud team that something was detected [1]. The third, "unknown", means no evidence of suspicious activity was found, and Apple states that it is not a confirmation the action is safe [10]. A queue rule can hold or step up on medium and high. It has no basis to release a payment faster on unknown. What happens next is the app's call: identity verification, a waiting period, or a warning [8].
The input list is the part a privacy reviewer will question. Apple's on-device disclosure cites device-use patterns, including the approximate number of phone calls and emails sent or received, and Apple Account information such as app downloads and content purchases [5]. The analysis may also include interaction patterns, timing, context and basic sensor data [6]. Apple says it does not analyze the contents of Photos, Messages or Mail [6]. The audit trail sits on the handset: Recent Activity lists the apps that asked, Reasons for Access shows which actions prompted them, and access can be switched off for individual apps [12].
Enrollment is a customer action. Share with App Developers is under Settings > Privacy & Security, and Apple notes the user may need to sign in to the App Store with an Apple Account to turn it on [11]. Changes to the main setting or to an app's access may take up to 24 hours to take effect [13]. So a bank cannot talk a caller through enabling the feature and then use the signal on that same call. A scammer coaching a victim to switch it off runs into the same delay.
Apple did not name any app, bank or payments provider that requests these assessments [14].
What to watch
- Whether any bank or payments app publishes an integration, and whether a high rating triggers a hold or only an on-screen warning.
- Enrollment figures for Share with App Developers, since the value of the signal to a fraud team tracks the share of customers who turn it on.
- Any change to Apple's documentation that moves scoring off the device or widens the input list beyond call, email, download and purchase patterns.