Researchers from Which? Travel recently exposed critical security vulnerabilities at Booking.com by successfully listing the British Prime Minister's official residence as a short-term rental.. The platform accepted payments and hosted fraudulent reviews for 10 Downing Street before finally removing the listing in late August.

Advertisement

The 10 Downing Street listing that bypassed AI security

On June 18, a researcher from Which? Travel created a listing titled "1 bedroom apartment in the heart of London," using the exact address of 10 Downing Street and a photograph of its famous black door. Despite Booking.com's claims of utilizing advanced artificial intelligence to verify accommodations, the listing went live and attracted 14 separate booking requests from users asking to stay at the Prime Minister's residence.

The security failure extended beyond mere visibility to financial transactions. According to the Which? investigation, Booking.com processed a payment from a representative using a separate account for a week-long stay; more than six weeks after the transaction, that money had still not been refunded. This demonstrates a systemic failure in the platform's ability to flag high-profile, impossible-to-rent landmarks.

Larry the Cat and the failure of review moderation

The investigation highlighted a complete breakdown in content moderation through the use of a fabricated review. A perfect 10-out-of-10 score mentioning Larry the Cat, the Prime Minister's well-known pet, appeared on the listing almost immediately, despite Booking.com's assertions that reviews require moderation.

Further risks were identified in the platform's communication tools. Researchers found that Booking.com's internal messaging system allowed them to send external links directing users to enter credit card details, a hallmark of phishing scams. As the report notes, competing platforms like Airbnb automatically block such external links to protect users, yet Booking.com failed to intercept these suspicious URLs.

The three-month window for identity verification

The ease of this deception is rooted in Booking.com's permissive onboarding policies. Under current company rules, hosts are not required to provide proof of ownership or photo identification until three months after a listing has gone live. This creates a significant window of opportunity for bad actors to solicit payments from unsuspecting travelers before any verification occurs.

This is not an isolated incident of lax oversight. a previous Which? investigation conducted in October 2024 revealed that in some instances, it took Booking.com 18 months to demand identity verification, with the fraudulent listing only being blocked after 20 months. This pattern suggests that the platform's verification process is reactive rather than preventative.

Ofcom's silence under the Online Safety Act

The failure to remove the 10 Downing Street listing until August 27—and only after Which? contacted the company—raises legal questions regarding the Online Safety Act. This legislation requires Booking.com to implement measures that prevent consumers from encountering fake listings and to remove fraudulent content swiftly.

However, a primary open question remains: why has the Office of Communications, known as Ofcom, taken so little action despite repeated evidence of fraud? Rory Boland , editor of Which? Travel, has called on the Prime Minister to pressure Ofcom to hold platforms accountable. while a Booking.com spokesman argued that this test does not reflect the experience of most users, the fact that the most famous door in Britain was not flagged suggests a profound gap in the platform's automated safeguards.