Apple is rolling out a new anti-scam feature called Impersonation Risk Detection, and it’s easy to miss because it’s off by default. The feature is built to catch social engineering scams, the kind where someone poses as your bank, Apple Support, or a government agency to talk you into sending money or handing over sensitive information.
According to Apple’s support documentation, the feature works quietly in the background and only steps in when you’re about to do something risky, like making a payment or changing your Apple Account security settings. Here’s how it works and how to turn it on.
Impersonation Risk Detection Watches for Suspicious Patterns, Not Specific Scams
Instead of blocking known scam numbers or flagging specific keywords, Impersonation Risk Detection looks at device and account activity to spot patterns associated with social engineering attempts. When you take a vulnerable action, like sending a payment or updating a password, the system runs an on-device risk check and returns one of three results:
- Unknown, meaning no suspicious indicators were found
- Medium, meaning some suspicious signals are present
- High, meaning the activity strongly matches known scam patterns
Apple says only that risk level gets shared with the app you’re using. The underlying data behind the assessment never leaves your device and Apple doesn’t see it either.
Impersonation Risk Detection is available starting with iOS 27 and iPadOS 27, and only inside apps that have built support for it. Older software versions won’t show the setting at all, so the first step for anyone who can’t find it is confirming their device has actually updated.
How to Turn On Impersonation Risk Detection
The feature lives inside a new Settings menu and has to be turned on manually. Follow these steps:
- Open the Settings app
- Tap Privacy & Security
- Tap Impersonation Risk Detection
- Turn on Share with App Developers
Apple may prompt you to authenticate with your Apple Account password during this last step. Once enabled, changes can take up to 24 hours to fully take effect across your apps, so don’t expect it to work instantly if you test it right after switching it on.
The same settings page lets you review which individual apps have access to the feature, so you can turn it off for specific apps without disabling it system-wide.
Apple’s own guidance flags one scenario directly: if someone contacts you and tells you to disable Impersonation Risk Detection, treat that as a sign you’re being scammed. Legitimate support staff, banks, and government agencies have no reason to ask you to turn off a security feature protecting your account.
Our Take
This is a smart move on Apple’s part because it targets the weakest link in most scams, which isn’t the technology, it’s the moment someone talks a person into acting against their own interest. Most of Apple’s security tools stop malware or unauthorized access. This one is aimed squarely at manipulation, and that’s a much harder problem to solve with software.
My only concern here is discoverability. Burying this inside Privacy & Security with an opt-in toggle means a lot of the people most vulnerable to these scams, older users especially, will never find it or turn it on unless someone walks them through it directly.