Booking.com accepted payment for fake 10 Downing Street listing, Which? finds

Consumer watchdog Which? created a bogus rental listing for the PM's residence and received payment. Booking.com faces calls for an Ofcom investigation over "systemic security failures".

Booking.com accepted payment for fake 10 Downing Street listing, Which? finds

Fake Downing Street rental stayed live on Booking.com for six weeks

Booking.com processed a payment for a fraudulent holiday rental listing of 10 Downing Street — and left it active for more than six weeks — according to The Guardian UK, which reported findings from consumer watchdog Which?.

Researchers at Which? created the listing on 18 June, describing the property as a "1 bedroom apartment in the heart of London", using the exact address and an image of the prime minister's official residence. The listing advertised a four-minute walk to the Houses of Parliament.

The booking window was opened briefly to allow a Which? researcher to complete a test transaction. A payment for a week-long stay was successfully processed by the platform. More than six weeks later, that money had still not been refunded, according to the watchdog.

The listing was eventually taken down on 27 August — ten weeks after it was created.

Fake review approved within minutes

Alongside the listing, Which? researchers uploaded a fabricated guest review describing the stay as "exceptional" and referencing time spent "hanging out with Larry the cat" — a nod to the Downing Street resident feline. Despite Booking.com sending an automated message stating the review would be checked by a team of moderators, it was approved and published almost immediately, the watchdog said.

Researchers also used Booking.com's internal messaging system to send an external URL requesting credit card details from a representative — a tactic commonly used by scammers to harvest financial information. Which? said Booking.com had previously indicated it had the capability to block external URLs in its messaging system when fraudulent activity was suspected, but did not do so in this instance.

"Systemic security failures"

Rory Boland, editor of Which? Travel, said: "If Booking.com's so-called sophisticated AI systems can't spot that 10 Downing Street is not a holiday rental, then it's no wonder scammers can exploit the platform so easily."

Which? said its investigation had "uncovered systemic security failures across the platform" and called on Ofcom, the UK's communications regulator, to open an investigation.

Booking.com disputes the characterisation

A Booking.com spokesperson pushed back on the findings, arguing the test was not representative of the platform's overall operation. "This limited test is not a true reflection of the experience of millions of listings on our platform," the spokesperson said. "The property added by Which? was not visible to customers or 'live' for the time period referenced."

The company said it uses "a range of checks, verification measures and artificial intelligence" that detect and remove the majority of fraudulent listings within 24 hours. It added that because the property was not set to open and bookable status, some of its automatic fraud controls were not triggered to fully remove the listing.

Ofcom signals limited scope

An Ofcom spokesperson said platforms carry legal obligations to remove illegal user-generated content once it comes to their attention. However, Ofcom noted that Booking.com falls outside the scope of forthcoming rules on paid-for fraudulent advertising. "Any change to that would be a matter for government," the spokesperson said.

The episode adds to growing pressure on online travel and accommodation platforms to tighten verification procedures for new property listings, particularly as regulators across the UK debate the extent of their powers under existing digital services legislation.

Source: The Guardian UK