Welcome to the Identity Theft Resource Center’s (ITRC) “Weekly Breach Breakdown” for October 9, 2026. I'm Tim Walden. Thanks to SentiLink for their continued support of the podcast and the ITRC.

Show Notes

Follow on LinkedIn: linkedin.com/company/idtheftcenter/
Follow on Instagram: instagram.com/idtheftcenter/
Follow on Facebook: facebook.com/IDTheftResourceCenter/
Follow on X: twitter.com/IDTheftCenter
Follow on TikTok: www.tiktok.com/@idtheftcenter_
Follow on YouTube: www.youtube.com/@IDTheftCenter

Show Transcript

Welcome to the Identity Theft Resource Center’s (ITRC) “Weekly Breach Breakdown” for October 9, 2026. I'm Tim Walden. Thanks to SentiLink for their continued support of the podcast and the ITRC. 

Each week, we break down the latest news in data privacy, scams and digital security. This week, we are looking at a clever new tool from Apple aimed at one of the trickiest threats out there: scams that rely on social engineering. 

We have all heard the advice a thousand times: create a passkey or pick strong passwords, use a password manager and turn on two-factor authentication. But con artists have adapted. Instead of trying to break through bank-level encryption, they just call or text you pretending to be your bank, a government agency or even a friend in trouble. They create an emergency, panic you and talk you into sending them cash or handing over access codes. Because you are the one pressing the send button, traditional security filters usually do not notice anything wrong.  

Apple’s latest operating system update, iOS 27, tries to tackle that exact problem with a feature called Impersonation Risk Detection.  

Here is how it works: when you go to do something major in a supported banking or payment app, like sending money or changing your password, the app can check in with your phone’s system to ask, "Does anything look off here?"  

Your iPhone quickly looks at local context clues. For example, are you actively on a strange phone call, rushing through an unusual transaction or moving much faster than normal? The system then hands the app a simple risk score: unknown, medium or high. If things look suspicious, the app can tap the brakes by making you wait, asking for an extra ID check or showing a warning before the money leaves your account.  

For anyone worried about privacy, Apple built this to run strictly on the device itself. Unlike similar tools on other devices, no one is reading your text messages, sifting through your emails or looking at your photos. In fact, the app requesting the check never sees your personal activity — it only gets that basic risk score.  

The catch? It is not switched on by default.  

If you want to use it, you have to go into Settings, tap Privacy & Security, find Impersonation Risk Detection and switch on Share with App Developers. From there, you can see exactly which apps have asked for a check and shut off access whenever you like.  

While it is great to see phone makers stepping in to help stop live fraud, remember that no software can catch every scam. Apple points out that an "unknown" rating does not automatically mean a situation is safe. The best defense is still taking a beat to breathe. If someone contacts you out of nowhere claiming your account is frozen or demanding money right now, hang up. Look up the official number yourself, make the call and verify the story before you touch your funds.  

If you want to learn more about how to spot impersonation scams or if you think you have been targeted, you can connect with an expert ITRC advisor for free. Call or text us at 888.400.5530, or chat with us live on our website at IDTheftCenter.org. 

Thanks again to SentiLink for their support of the ITRC and this podcast. Please hit the like button for this episode, and subscribe wherever you listen to podcasts. We'll be back next week with a new episode of the “Weekly Breach Breakdown”. I'm Tim Walden. Until then, thanks for listening. 

Listen On