Apple added Impersonation Risk Detection to iOS 27 and iPadOS 27 to help participating applications identify potential social-engineering and identity-impersonation scams before sensitive actions. Apps can request an assessment for events such as payments, password changes, or sharing account details, and receive an Unknown, Medium, or High risk rating; each developer decides whether to warn the user, require additional identity verification, delay the action, or apply other controls.
The capability is disabled by default and requires users to enable Share with App Developers; activation can take up to 24 hours. Apple says its assessment uses relevant Apple Account and device signals while Apple neither receives the underlying interaction-assessment data nor inspects content in Mail, Messages, or Photos, although it can learn the action category for which an app requests a risk assessment.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Apple introduced Impersonation Risk Detection to help supported Apple and third-party apps identify potential social-engineering and impersonation scams before sensitive actions such as payments, password changes, or sharing account information. The feature returns Unknown, Medium, or High risk assessments, while participating apps determine the resulting safeguards.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.