Researchers from Which? Travel recently exposed significant security vulnerabilities on Booking.com by successfully creating a fake holiday rental listing for 10 Downing Street. The test demonstrated that the platform allows fraudulent properties to go live and process payments without immediate verification.

Advertisement

The 10 Downing Street listing that attracted 14 hopeful guests

On June 18, the Which? Travel team established a listing described as a "1 bedroom apartment in the heart of London," using the official address of the British Prime Minister's residence and a well-known image of the building. Despite the high profile of the location, the listing was accepted by Booking.com without any immediate red flags being raised by the platform's automated systems.

The vulnerability of users became apparent almost immediately . according to the Which? report, 14 different users contacted the fake listing to inquire about staying at the address during a brief window when the booking option was opened. This highlights a dangerous gap in how Booking.com verifies the legitimacy of high-profile or improbable addresses before they are visible to the public.

Unrefunded payments and the 'Larry the Cat' review

The security failures extended beyond simple listing creation to financial processing.. booking.com processed a full payment from a Which? researcher for a week-long stay at the fake Downing Street property; however, as reported by Which?, that money had still not been refunded more than six weeks after the transaction.

The platform's moderation of user-generated content also proved ineffective. On August 11, researchers posted a fraudulent 10-out-of-10 rating that specifically mentioned Larry the Cat, the famous resident feline of Downing Street. While Booking.com claimed reviews are checked by moderators, this specific review appeared almost instantly, suggesting that the moderation process is either superficial or entirely automated and easily bypassed.

Why Booking.com failed to block phishing links unlike Airbnb

A critical component of the Which? investigation involved testing the platform's internal messaging system for phishing risks. Researchers found they could send external links via Booking.com messages, directing a test account to a third-party site to enter credit card details to "confirm" a booking. This is a common tactic used by scammers to steal financial data from unsuspecting travelers.

This behavior stands in stark contrast to other industry giants. The report notes that platforms like Airbnb automatically block external web links in messages to protect users from phishing. While Booking.com stated it has the ability to block URLs when fraudulent activity is suspected, it failed to intercept the link in this specific test, leaving a clear pathway for potential cybercriminals.

A three-month window for fraud and the 18-month listing failure

The Downing Street incident is not an isolated event but part of a recurring pattern of lax oversight. In October 2024, Which? conducted another test where a fraudulent listing was created in just 15 minutes. That specific listing remained active for 18 months before Booking.com requested proof of identity, and it was only removed 20 months after creation when the researchers refused to provide documentation.

The root of this issue appears to be a systemic policy flaw. According to Which?, Booking.com's current policies do not require hosts to provide photo identification or proof of property ownership until a listing has been live for three months. This creates a massive window of opportunity for "hit-and-run" scammers to list fake properties, collect payments, and disappear before any verification is triggered.

Ofcom's perceived inaction under the Online Safety Act

The legal stakes for Booking.com have risen with the introduction of the Online Safety Act,which mandates that platforms implement measures to prevent consumers from encountering fake listings. Despite these legal requirements, Which? argues that Ofcom,the UK regulator, has failed to hold Booking.com accountable despite repeated evidence of fraud.

Rory Boland,the editor of Which? Travel, has called on the Prime Minister to pressure Ofcom to enforce the Online Safety Act more aggressively. This regulatory gap leaves users to rely on an ineffective AI chatbot for support, as many travelers have already reported arriving at properties only to find their bookings were entirely fake.