- Published
Consumer group Which? says it was able to create a fake listing for 10 Downing Street on travel giant Booking.com.
The UK watchdog said its researchers were able to book a bogus stay at the prime minister's address - as well as leave a fake review noting "hanging out" with resident mouser Larry the cat as a highlight.
It said despite clear signs it was fake, Booking.com did not remove the listing until two months after it was uploaded.
"This limited test is not a true reflection of the experience of millions of listings or reviews published on our platform," a Booking.com spokesperson told the BBC.
They said because Which?'s listing was not "live" on its site across the two months it was present, "some of our automatic fraud controls were not triggered to completely remove the closed listing".
People could only see the listing and request to book the property during a 20-minute window opened by Which? so its researchers could try to book it.
Booking.com's spokesperson added "a range of checks and verification measures" help secure the site, and technologies such as AI "help us detect and remove the majority of fraudulent listings within 24 hours".
But Which? Travel editor Rory Boland said its checks had been shown to be "unfit for purpose".
"If Booking.com's so-called sophisticated AI systems can't spot that 10 Downing Street is not a holiday rental, then it's no wonder scammers can exploit the platform so easily," he said.
"It would be laughable that we were able to list the UK's most famous address for rent, if the consequences weren't so devastating for holidaymakers, who risk losing thousands of pounds to bogus listings and phishing links."
It is not the first time the site has faced criticism over its security efforts and customer service.
'Prime city centre location'
Which?'s listing, uploaded to Booking.com on 18 June, advertised a "1 bedroom apartment in the heart of London".
It used images of the iconic 10 Downing Street front door, listed at its address - with a description referring to the one bedroom space as "a prime city centre location".
In the 20 minutes that Which? permitted customers to request a stay at its fake 10 Downing Street property, it said 14 people asked to do so.
Only the booking request from a person known to be a Which? researcher was accepted.
The watchdog's team also sent the researcher a message within Booking.com's system asking them to click an external link to confirm their payment details - something booking sites typically block to prevent customers being scammed.
But Which? said that in this instance, Booking.com did not flag or remove the external link it sent.
Booking.com said it had "visible reminders to not click on links customers are not confident about, and booking confirmations also provide further guidance, including details of the agreed payment schedule".
The fake review left by Which? also seemingly passed the site's checks, despite bearing all the hallmarks of a joke.
"It was unbelievable that Booking.com let us stay at 10 Downing Street - the home of the UK PM!" it said.
The listing itself was removed by the platform on 27 August.
Some customers have previously accused the firm of failing to protect them from falling victim to cyber-criminals.
"Fraud affects many industries, and 80% of UK adults believe scams are becoming more sophisticated," said Booking.com's spokesperson - adding it was continuing to strengthen its defences in the face of this challenge.
Which?, meanwhile, said more should be done to force booking sites to swiftly remove false listings under the Online Safety Act (OSA).
The Act requires firms which have identified illegal content, including fraudulent material, on their sites to show they are committed to removing it.
Boland said Ofcom, which enforces the OSA, should be encouraged use it to "crack down on irresponsible online platforms that leave consumers wide open to fraud".
"For illegal content generated by users, platforms have existing legal duties that mean they must take it down swiftly once they become aware of it," an Ofcom spokesperson told Which?.
-
Booking.com customers warned of 'reservation hijacking' after hack
- Published15 April
-
Holidaymaker loses â¬1,800 in phishing scam
- Published14 October 2025
-
Tourists descend on private home in Booking.com scam
- Published3 August 2022
Sign up for our Tech Decoded newsletter to follow the world's top tech stories and trends. Outside the UK? Sign up here.