iOS 27 has a hidden anti-scam setting — here’s why every iPhone user should turn it on
Thanks to iOS 27, your iPhone can now tell if you're being scammed. Here's where to find the setting Apple leaves off by default
With iOS 27, Apple is introducing a native line of defense called Impersonation Risk Detection to tackle increasingly sophisticated social engineering scams.
From convincing fake text messages to callers posing as government agents or bank representatives, these attacks are notoriously difficult to block because traditional phone security struggles when a victim is tricked into voluntarily initiating a payment or sharing account details.
Designed to spot potential fraud in real time, this new system-level feature in iOS 27 acts as a built-in safety net, warning you (and supported third-party apps), when an interaction shows signs of a scam before you hand over sensitive information or money.
How Apple spots scams without reading your private messages
Unlike invasive security tools that scan your personal files, Impersonation Risk Detection is built around Apple’s privacy-first architecture.
When you attempt a sensitive action inside a supported app, such as sending a wire transfer, making a high-value payment, or changing critical security settings — the app can request a risk assessment from iOS 27.
On the device, Apple analyzes interaction timing, behavioral patterns, context, and basic sensor data to determine if you might be acting under the influence of a scammer.
Based on this on-device analysis, iOS 27 assigns one of three risk levels:
Get instant access to breaking news, the hottest reviews, great deals and helpful tips.
- Unknown: No actionable data or normal usage pattern detected.
- Medium: Minor unusual activity flagged.
- High: Significant indicators of suspicious or manipulated behavior detected.
Crucially, Apple never reads or analyzes the content of your Photos, Messages, or Mail.
The app only receives the final risk level score, allowing it to trigger protective measures like requiring extra identity verification, delaying a transaction, or displaying an urgent warning banner.
Why the feature is turned off by default
Because Impersonation Risk Detection requires sharing limited event signals with app developers and system diagnostic servers, Apple leaves the feature disabled by default upon updating to iOS 27.
To take advantage of the protection, you must manually opt in through your settings.
How to turn on Impersonation Risk Detection in iOS 27
To set it up, open Settings on your iPhone, scroll down, and tap Privacy & Security.
Next, locate and select Impersonation Risk Detection, and then simply toggle the main switch to on to grant consent for supported apps to request real-time risk assessments.
Apple notes that after enabling the toggle, it can take up to 24 hours for the protection signals to fully activate across compatible apps.
Once active, you can return to this same menu at any time to view Recent Activity, giving you full visibility into which apps have requested a risk assessment and the specific actions that triggered them.
Will you be turning on Impersonation Risk Detection, or do you prefer to keep sharing toggled off? Let us know in the comments.
Follow Tom's Guide on Google News and add us as a preferred source to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button!
More from Tom's Guide
Kaycee is Tom's Guide's How-To Editor, known for tutorials that get straight to what works. She writes across phones, homes, TVs and everything in between — because life doesn't stick to categories and neither should good advice. She's spent years in content creation doing one thing really well: making complicated things click. Kaycee is also an award-winning poet and co-editor at Fox and Star Books.
Next Badge:
More Comments/Likes Until Your Next Badge
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.