Apple introduced a new setting called Identity Spoofing Risk Detection in iOS 27, as described in a support document published on September 14. This feature is designed to identify scams where victims are tricked into approving actions themselves, often over the phone with a fake bank representative. The setting is turned off by default, meaning users must manually enable it to gain protection. Shortly after iOS 27 was released, Apple issued an update, iOS 27.0.1, to address bugs and improve the system's stability.
In early September, the Observatory for Payment Security, a unit of the Bank of France, released its annual report, estimating that fraud through manipulation reached 516 million euros in 2025. This represents a 34% increase from the previous year and accounts for 41.6% of the total 1.24 billion euros in payment fraud. The report noted that the majority of this fraud occurred through direct transfers, totaling 376 million euros. Traditional security measures like two-factor authentication are often ineffective in such cases because they only confirm that the account holder is acting, not whether they are being coerced by a scammer.
With the Identity Spoofing Risk Detection feature, when a sensitive action is initiated in a compatible app—such as making a payment or changing a password—the app can request an evaluation from iOS. According to Apple, the iPhone uses data from its sensors and analyzes the speed and context of user interactions to determine a risk level: unknown, medium, or high. The app receives only the risk level, and the data used to calculate it remains on the device. Based on this, the app may ask for identity verification, delay the action, or show a warning. A risk level of "unknown" does not guarantee safety, only that no suspicious behavior was detected. The effectiveness of the feature depends on app developers, as not all apps are compatible with the detection tool from the start. Apple has not released a list of compatible apps, and the feature only works in third-party apps that have integrated it.
The feature is disabled by default because it sends some information to app developers and Apple diagnostic servers. Apple acknowledges that it records the type of action attempted in the app during each evaluation request, which is why the feature is disabled to protect user data. To activate the setting on an iPhone or iPad with iPadOS 27, users must go to Settings, then Privacy and Security, scroll down to Identity Spoofing Risk Detection, and enable "Share with App Developers." Users may need to log in to the App Store with their Apple account. The same menu shows which apps have requested an evaluation and for what action. Users can also limit access for specific apps. Apple warns that changes to this setting may take up to 24 hours to take effect, a delay that is intentional. If someone asks a user to disable the feature, Apple advises that this is a sign of a scam, and the scammer will not be able to exploit it during the call.
The Identity Spoofing Risk Detection feature is available on all iPhones compatible with iOS 27, including models from the iPhone 11 and the second-generation iPhone SE up to the iPhone 18 Pro and iPhone 18 Pro Max.
Apple Introduces Identity Spoofing Risk Detection in iOS 27 to Combat Payment Fraud
AI-rewritten from original reportingHow it works
appleios-27fraud-detectionscamsbank-of-francepayment-security



