Consumer group Which? exposes Booking.com security flaw with fake 10 Downing Street listing
Quick Look
UK consumer watchdog Which? created a fake Booking.com listing for 10 Downing Street, which remained active for two months despite clear signs of fraud, and during a 20-minute test window, 14 users attempted to book the property, highlighting vulnerabilities in the platform's fraud detection systems.
AI-generated summary
Why It Matters
Booking.com has previously faced criticism over its security efforts and customer service, prompting Which? to conduct a test to evaluate the platform's ability to detect fraudulent listings.
Consumer group Which? says it was able to create a fake listing for 10 Downing Street on travel giant Booking.com.
The UK watchdog said its researchers were able to book a bogus stay at the prime minister's address - as well as leave a fake review noting "hanging out" with resident mouser Larry the cat as a highlight.
It said despite clear signs it was fake, Booking.com did not remove the listing until two months after it was uploaded.
"This limited test is not a true reflection of the experience of millions of listings or reviews published on our platform," a Booking.com spokesperson told the BBC.
They said because Which?'s listing was not "live" on its site across the two months it was present, "some of our automatic fraud controls were not triggered to completely remove the closed listing".
People could only see the listing and request to book the property during a 20-minute window opened by Which? so its researchers could try to book it.
Booking.com's spokesperson added "a range of checks and verification measures" help secure the site, and technologies such as AI "help us detect and remove the majority of fraudulent listings within 24 hours".
But Which? Travel editor Rory Boland said its checks had been shown to be "unfit for purpose".
"If Booking.com's so-called sophisticated AI systems can't spot that 10 Downing Street is not a holiday rental, then it's no wonder scammers can exploit the platform so easily," he said.
"It would be laughable that we were able to list the UK's most famous address for rent, if the consequences weren't so devastating for holidaymakers, who risk losing thousands of pounds to bogus listings and phishing links."
It is not the first time the site has faced criticism over its security efforts and customer service.
In the 20 minutes that Which? permitted customers to request a stay at its fake 10 Downing Street property, it said 14 people asked to do so.
Only the booking request from a person known to be a Which? researcher was accepted.
The watchdog's team also sent the researcher a message within Booking.com's system asking them to click an external link to confirm their payment details - something booking sites typically block to prevent customers being scammed.
But Which? said that in this instance, Booking.com did not flag or remove the external link it sent.
Booking.com said it had "visible reminders to not click on links customers are not confident about, and booking confirmations also provide further guidance, including details of the agreed payment schedule".
The fake review left by Which? also seemingly passed the site's checks, despite bearing all the hallmarks of a joke.
"It was unbelievable that Booking.com let us stay at 10 Downing Street - the home of the UK PM!" it said.
The listing itself was removed by the platform on 27 August.
What to Watch
AI outlook — possibilities, not facts
Booking.com will implement additional verification measures for property listings
Likely · Within weeks
Which? will continue to monitor and test major online platforms for consumer protection issues
Very likely · Within months
Open Questions
- How many other fake listings may currently exist on Booking.com?
- What specific improvements will Booking.com make to its fraud detection systems?
- Will regulatory bodies investigate Booking.com's security practices following this exposure?






