The consumer advocacy group Which? has challenged the security protocols of Booking.com after successfully creating a fraudulent listing for 10 Downing Street. The watchdog’s researchers managed to advertise the Prime Minister’s official residence as a one-bedroom apartment in central London, complete with a description highlighting its proximity to Big Ben. Despite the obvious nature of the hoax, the listing remained active on the platform for two months before being removed on August 27.
During the period the listing was active, researchers were able to book a stay and even post a fake review, which claimed that “hanging out” with Larry the cat, the resident mouser, was a highlight of the experience. According to Which?, the platform’s moderation systems failed to flag the review, which was published shortly after it was submitted. The group noted that the listing was only visible for a 20-minute window when they opened it for testing, during which 14 people attempted to book the property. Only the researcher’s booking request was accepted.
The investigation also revealed that the fake host sent a message through the platform’s internal system requesting that the guest click an external link to confirm payment details. This tactic is a common method used by scammers to bypass security, yet the platform failed to flag or remove the link. Which? Travel editor Rory Boland criticized the site’s defenses as “unfit for purpose,” arguing that if automated systems cannot identify that the UK’s most famous address is not a holiday rental, they are failing to protect consumers from significant financial risk.
In response to the findings, a spokesperson for Booking.com stated that the “limited test” conducted by the group was “not a true reflection of the experience of millions of listings or reviews published on our platform.” The company explained that because the listing was not live for the duration of the two months, certain automatic fraud controls were not triggered to fully remove it. The spokesperson added that the company employs a range of verification measures and artificial intelligence to detect and remove the majority of fraudulent listings within 24 hours.
Booking.com further emphasized that it provides visible reminders to users, advising them not to click on suspicious links, and includes guidance within booking confirmations regarding payment schedules. The company acknowledged that fraud is a persistent challenge across many industries, noting that 80% of UK adults believe scams are becoming increasingly sophisticated. They stated they are continuing to strengthen their defenses to address these threats.
Which? is now calling for more robust enforcement under the Online Safety Act (OSA), which requires platforms to take swift action against illegal content, including fraudulent material, once they are aware of it. Boland urged Ofcom, the regulator responsible for the OSA, to take a firmer stance against irresponsible platforms. An Ofcom spokesperson confirmed that platforms have existing legal duties to remove illegal user-generated content promptly once they are notified of its existence. The report also notes that if the consequences weren’t so devastating for holidaymakers, who risk losing thousands of pounds to bogus listings and phishing links, it would be laughable that we were able to list the UK’s most famous address for rent. The report also notes that it is not the first time the site has faced criticism over its security efforts and customer service. The report also notes that uploaded to Booking.com on 18 June, advertised a “1 bedroom apartment in the heart of London”, which?’s listing. The report also notes that listed at its address – with a description referring to the one bedroom space as “a prime city centre location”, it used images of the iconic 10 Downing Street front door. The report also notes that a description for the property said it was ‘situated on 10 Downing Street’ and only a short walk of ‘400 metres’ to Big Ben. The report also notes that also seemingly passed the site’s checks, despite bearing all the hallmarks of a joke. The report also notes that some customers have previously accused the firm of failing to protect them from falling victim to cyber-criminals.











Comments