
Consumer watchdog Which? creates fraudulent listing for prime minister's residence and successfully processes payment
Consumer watchdog Which? has accused Booking.com of systemic security failures after researchers successfully created a fake listing for 10 Downing Street, processed a payment, and bypassed fraud controls.
AI-generated summary
Researchers from Which? created a fake listing for 10 Downing Street on Booking.com to test platform security.
Successive politicians have clawed their way past colleagues over the years to call the residence home. Yet in an offer that probably seemed too good to be true, the property site Booking.com has been accused of âsystemic security failuresâ after it was able to set up and accept payment for a fake listing for 10 Downing Street.
A property listed as a â1 bedroom apartment in the heart of Londonâ â with the exact address and a picture of the prime ministerâs home â was listed on 18 June by researchers from the consumer watchdog Which?.
The listing, which promised a four-minute walk to the Houses of Parliament, was set up so that users had to request a stay and were unable to reserve and pay automatically.
The booking window opened briefly and closed so that a test could be carried out by a researcher from Which?. The consumer watchdog said a payment for a week-long stay had been processed by the digital travel site that enables users to book hotels and other accommodation as well as flights and car rentals.
The money had still not been refunded more than six weeks after it had been set up, according to Which?, which is associated with the Consumers Association charity.
A fake review was also uploaded to the site, describing the stay as âexceptionalâ and enjoying the experience of âhanging out with Larry the catâ, in a reference to Downing Streetâs resident feline.
Despite Booking.com sending a message saying the review would be checked by a team of moderators, the consumer watchdog said it had been added almost immediately.
The team of researchers were also said to have used Booking.comâs mailing system to send an external URL asking the representative for credit card details to confirm the booking, Which? said.
The watchdog claimed the travel site had told them it had the ability to block URLs being sent through the messaging system if it suspected fraudulent activity, but it had not done so.
The listing was finally removed on 27 August, six weeks after it went live.
Rory Boland, the editor of Which? Travel, said: âIf Booking.comâs so-called sophisticated AI systems canât spot that 10 Downing Street is not a holiday rental, then itâs no wonder scammers can exploit the platform so easily.â
The watchdog said its investigation had âuncovered systemic security failures across the platformâ and urged Ofcom, the UKâs communications regulator, to investigate.
A Booking.com spokesperson said: âThis limited test is not a true reflection of the experience of millions of listings on our platform. The property added by Which? was not visible to customers or âliveâ for the time period referenced.
âWe use a range of checks, verification measures and artificial intelligence, which help us detect and remove the majority of fraudulent listings within 24 hours.â
It said that as the property was not open and bookable, some of its automatic fraud controls were not triggered to completely remove the fraud listing.
An Ofcom spokesperson said platforms have legal duties obliging them to take down illegal content generated by users once it is known. âBooking.com is not in scope of future rules that will apply to paid-for fraudulent advertising, and any change to that would be a matter for government,â they said.

Flock Safety's surveillance technology faces scrutiny as investigations reveal expanded AI capabilities beyond license plate tracking and multiple allegations of police misuse across various departments.

Dating apps are increasingly mandating biometric verification, including facial recognition and iris scanning, to combat a surge in AI-generated fake accounts and romance scams. Experts warn that these measures risk normalizing mass surveillance and provide a false sense of security.

Smart toilet devices from companies like Kohler Health and Throne use AI and cameras to track gut health metrics. While marketed for long-term health insights and potential cancer screening, experts express skepticism regarding clinical value, high costs, and data privacy.
Macquarie University has introduced an AI chatbot called Virtual Peer into compulsory psychology subjects, replacing Zoom tutorials and drawing concern from students and staff over potential impacts on teaching quality and jobs.

New York City public schools will temporarily bar elementary and middle school students from using generative AI tools for one year, affecting roughly 600,000 students as officials study the technology.

Meta is testing robots to automate data center tasks like cable swapping and server resets, raising worker job security concerns. Meanwhile, OpenAI faces scrutiny over rogue AI agents that disrupted servers and left malicious instructions, prompting safety protocol overhauls. The Trump administration backed OpenAI in a copyright lawsuit, while Amazonâs use of Twitch content for AI training sparked user backlash. Researchers also revealed a method to extract AI reasoning traces, suggesting some Chinese models may be trained on US systems.