Fake Downing Street Listing on Booking.com Exposes Serious Platform Security Flaws

Two months elapsed between the fake Downing Street listing’s creation and removal, during which it was not publicly visible and automated fraud controls were not triggered; Booking.com told Which? that 'This limited testing does not accurately reflect the experience of the millions of listings and reviews published on our platform.'
Which? testers processed a week-long payment using a separate account and, despite the listing’s eventual removal, the funds had not been returned even six weeks after the page went live.
Testers used Booking.com’s messaging system to send an external URL asking the property’s representative for credit card details to confirm the booking; Which? said Booking.com could block such URLs, but it did not.
Which? reported numerous scam-related complaints and hundreds of travelers encountering fake listings linked to Booking.com, underscoring broader security concerns.
Removal of the fake listing occurred around August 27, about six weeks after it went live.
Consumer watchdog Which? exposed serious security gaps at Booking.com by creating a fake listing for 10 Downing Street, the UK Prime Minister's official residence. The phony rental, complete with the exact address and photo of the iconic black door, stayed online for roughly six weeks and processed a week-long booking payment that went unrefunded, Which? reported.
Booking.com's automated fraud controls failed to catch the listing or the bogus review praising the stay and mentioning Larry the Cat, the Prime Minister's pet. Which? argues the incident reveals that Booking.com's safeguards are "unfit for purpose" and highlights growing risks of scams and phishing attacks targeting travelers on the platform.
Which? testers created the 10 Downing Street listing in early July, pricing it as a 1-bedroom apartment available for weekly stays. The listing required manual approval before bookings could go through—a safety measure that failed to stop the payment from processing. Despite claims that Booking.com removes suspicious listings within 24 hours, the fake property remained online for approximately six weeks before removal around August 27.
Even after the listing was taken down, Which? confirmed the booking funds had not been returned six weeks later. The watchdog also posted a fake review claiming a wonderful stay and referencing Larry the Cat. Booking.com approved the review quickly, despite Which? saying it was obviously fabricated and should have been flagged by moderation systems.
Which? testers used Booking.com's built-in messaging system to send property inquiries containing an external URL. In those messages, they asked for credit card details to "confirm" the booking—a classic phishing tactic. Booking.com did not block the suspicious links or flag the requests, even though the platform has the technical ability to prevent such URLs from being sent through its messaging channel.
Booking.com responded to Which?'s findings by stating that its automated fraud detection and AI tools catch most issues within 24 hours. The company told Which? that "this limited testing does not accurately reflect the experience of the millions of listings and reviews published on our platform" and emphasized that the test does not represent typical platform activity.
However, Which? has documented hundreds of complaints from travelers who encountered fake listings tied to Booking.com, pointing to wider systemic concerns about scams beyond this single test. The watchdog argues that Booking.com's defenses leave users vulnerable to fraud and phishing, regardless of how many listings the platform processes daily.
Publishers
10
Articles
22
Reach
32