iOS 27: Why you should learn to love Impersonation Risk Detection

if ( !emtpy($headline_subheadline ) ) : ?>
Apple’s new scam-prevention tool opens a new line of defense against online crime.

[…Keep reading]

iOS 27: Why you should learn to love Impersonation Risk Detection

iOS 27: Why you should learn to love Impersonation Risk Detection

if ( !emtpy($headline_subheadline ) ) : ?>

Apple’s new scam-prevention tool opens a new line of defense against online crime.
endif; ?>

Credit: Apple

I once had a friend who gave $1,000 to an online fraudster who claimed to be a tax assessor. My own father (bless his soul) once managed to hand over several hundred pounds to a lawyer from Africa promising to send him funds. 

We know it happens. 

We know people impersonate trusted entities to trick us into giving them our money. It’s a scam, one that’s taking place at every level of digital existence. 

Apple is here to help.

Yet another great feature new to iOS 27, Apple’s new scam-prevention tool is a welcome intervention, giving individuals and businesses another line of defense against social engineering scams. While it’s not perfect, it is here, and every Apple user — particularly those working in or managing regulated industries, or any business at all that feels it may be a target for scams, fraud, or socially-engineered crimes — should take a look. According to most security reports, that effectively includes all of us. 

What is Impersonation Risk Detection?

On its support site, Apple explains several hypothetical attack scenarios the feature is designed to protect against, such as when an attacker convincingly poses as a government agency or some other trusted entity to trick you into making a payment or changing account or login details. 

These things are very hard for traditional security protection to spot, in part because you are choosing to take the action — security can’t tell you’ve been tricked. Apple’s new system works to bridge the gap. It looks at information it knows about your device and your Apple Account and tries to spot when you’re being scammed, delivering its own risk assessment.

While Impersonation Risk Detection is a new system-level tool, it does require user consent to permit supported apps to ask the operating system for a risk assessment if the user does something that could be in response to a scam. 

That assessment takes the form of a risk level that helps the app decide what to do next. This will usually trigger additional security steps on the part of that third-party app, including a request for identification, a delay in a transaction, or a warning to let you know you might be being scammed.

Supported apps may request one of these risk assessments when you do things like make a payment or change security settings for your account. Apple tells us these assessments come in the form of one of three levels: Unknown, Medium, or High, with High meaning significant signs of suspicious activity have been detected. It is important to note that while Apple raises these flags, it’s the app that makes the decision on what to do next. Apple’s part ends once it raises the warning.

The settings for the feature also let you take a look at which apps have requested a risk assessment, and why. At least, it will once the feature is activated and has been running for a while. You’ll find a list of requesters in Recent Activity, while the Reasons for Access will show you what actions prompted the request. 

Who sees what?

If you do choose to share information with developers, they will only get the scam warning signals generated using information about your device and Apple Account. Apple, however, will learn the type of action you attempted in the app, and may also learn relevant details such as the number of calls or emails you’ve made. 

This is what Apple says it checks:

On the device, Apple analyzes interaction patterns, timing, context, and basic sensor data to generate the risk level. 

Apple never analyzes the content of your Photos, Messages, or Mail.

Apple learns the type of action you attempted in the app only when the app requests the risk assessment.

Apps receive only the risk level, not the data.

How to enable Impersonation Risk Detection

Because the tool requires that some of your information is shared, Apple has left Impersonation Risk Detection off by default. Here’s how to enable it or just take a look:

Open Settings > Privacy & Security.

Scroll down the pane to find the Impersonation Risk Detection section, which sits beneath the App Advertising item. 

Tap this, and on the next page you’ll find a toggle to share information with developers of apps that support the feature. 

Toggle this to on for the protection to kick in. Apple warns it may take four hours to come into effect. 

Once approved, compatible apps can request Apple’s Impersonation Risk Detection signals to see if your device or account shows signs that you’re being scammed. And hopefully you — or my dad — won’t get fooled again.

Now please subscribe to my daily, human-curated Apple-related news headline feed at The Core, or follow me on BlueSky, LinkedIn, or Mastodon.

AppleiOSOperating SystemsSecurityVendors and Providers

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.