Consumer protection organisation Which? has demonstrated significant vulnerabilities in Booking.com's fraud detection systems by successfully creating and maintaining a fake holiday rental listing for 10 Downing Street, the official residence of the UK Prime Minister.
Researchers at the watchdog uploaded the bogus property on 18 June and were able to accept booking requests from members of the public during a 20-minute window. The listing remained on the platform for two months before Booking.com removed it on 27 August, despite containing obvious indicators of fraudulence. During the time the listing was accessible, 14 people attempted to book stays at the Prime Minister's address.
According to Which?'s own account of the test, the property was advertised at £55 per night and the organisation was able to accept bookings within hours without being required to demonstrate ownership or verify their identity. The fake listing described a "1 bedroom apartment in the heart of London" situated at the Downing Street address, claiming it was only 400 metres from Big Ben and marketing it as "a prime city centre location".

The watchdog's team also submitted a deliberately humorous review stating: "It was unbelievable that Booking.com let us stay at 10 Downing Street - the home of the UK PM!" This review passed the platform's moderation checks and was published on the listing.

Which? Travel editor Rory Boland characterised Booking.com's security measures as fundamentally inadequate.
If Booking.com's so-called sophisticated AI systems can't spot that 10 Downing Street is not a holiday rental, then it's no wonder scammers can exploit the platform so easily. It would be laughable that we were able to list the UK's most famous address for rent, if the consequences weren't so devastating for holidaymakers, who risk losing thousands of pounds to bogus listings and phishing links.
How did Booking.com respond?
A Booking.com spokesperson told the media that the test represented only a limited exercise and did not reflect the typical experience across millions of listings on the platform. The company stated that because Which?'s listing was not "live" across the full two-month period—it was only accessible during the 20-minute booking window—certain automatic fraud detection systems were not fully activated to remove the closed listing.
The platform emphasised that it employs "a range of checks and verification measures" and uses artificial intelligence technology to identify and remove the majority of fraudulent listings within 24 hours. However, Which?'s broader investigation found an "easily hacked messaging system" and a lack of identity checks on property owners, suggesting systemic weaknesses beyond the specific test case.
What security failures did the test reveal?
The investigation exposed multiple layers of inadequate protection. During the test, Which?'s researcher received a message through Booking.com's internal system asking them to click an external link to confirm payment details—a tactic commonly used by scammers to steal financial information. Booking.com did not flag or remove this external link, despite booking platforms typically blocking such requests to prevent customer fraud.
The watchdog's team also noted that Booking.com's messaging system can be abused by scammers, including through fake requests for payment or links. Booking.com responded by pointing to "visible reminders to not click on links customers are not confident about" and stating that booking confirmations provide guidance on agreed payment schedules, but these warnings did not prevent the fraudulent message from being sent in the first place.
Is this the first time Which? has tested the platform?
This investigation represents an escalation of Which?'s scrutiny of Booking.com's security. According to Which?'s published findings, the organisation conducted a similar fake-listing test in October 2024, indicating that concerns about the platform's vulnerability to fraudulent properties have persisted for at least eight months. The repeated ability to exploit these weaknesses suggests that Booking.com has not substantially strengthened its defences in response to earlier warnings.
What are the broader implications for travellers?
Booking.com has faced mounting criticism over its security and customer service record. The platform has previously been accused by customers of failing to protect them from cyber-criminals, and the company acknowledged that "fraud affects many industries, and 80% of UK adults believe scams are becoming more sophisticated." The company stated it was continuing to strengthen its defences in response to these challenges.
Which? has called for stronger regulatory action, arguing that more should be done to compel booking sites to swiftly remove false listings under the Online Safety Act. The watchdog urged Ofcom, which enforces the legislation, to use its powers to "crack down on irresponsible online platforms that leave consumers wide open to fraud."
An Ofcom spokesperson acknowledged that the Online Safety Act requires firms to demonstrate commitment to removing illegal content, including fraudulent material, once they become aware of it. The Act stipulates that platforms have existing legal duties to take down such content swiftly.
Key Facts
- Which? created a fake 10 Downing Street listing on Booking.com on 18 June, advertised at £55 per night, and received 14 booking requests within 20 minutes of opening it to the public
- The fraudulent listing remained on the platform for two months before removal on 27 August, despite obvious signs of being fake, including a humorous review about meeting the Prime Minister's cat
- The test revealed that Booking.com did not block external payment links sent through its messaging system and did not require identity verification or proof of property ownership before accepting bookings
- Which? conducted a similar fake-listing test in October 2024, suggesting persistent vulnerabilities in Booking.com's fraud detection systems over an eight-month period
- The watchdog is calling for Ofcom to use the Online Safety Act to enforce swifter removal of fraudulent listings and greater accountability from booking platforms







