Consumer watchdog Which? listed a fake stay at 10 Downing Street on Booking.com, in order to expose failings in the travel company’s security checks.

In the ‘brief’ time the listing was live, 14 people attempted to book the accommodation (although Which? did not take payment).

Which? researchers were however able to process a real payment from their own team, which is yet to be refunded, more than six weeks later.

The consumer champion says this experiment is evidence that Booking.com’s security controls have ‘glaring gaps’ and exposes travellers to fraud.

Just a stone’s thrown from Parliament

On June 18, a Which? researcher listed a property on Booking.com, headlined ‘1 bedroom apartment in the heart of London.’

The listing included the exact address and a photo of the front door of 10 Downing Street, promising an ideal location ‘just four minutes on foot to the Houses of Parliament.’

It was purposefully set up so that users had to request a stay rather than book instantly.

Which? say the booking window was opened ‘very briefly’ for 20 minutes. During this opening, 14 people attempted to book, but were not charged.

Booking.com also processed a payment from a Which? researcher for a week long stay at the fake listing. The money is yet to be refunded.

{“@context”:”https://schema.org”,”@type”:”VideoObject”,”name”:”Tourists duped into booking stays at 10 Downing Street on Booking.com”,”contentUrl”:”https://videos.metro.co.uk/video/met/2026/09/01/8753574626422047618/480x270_MP4_8753574626422047618.mp4″,”description”:”14 people have tried to book 10 Downing Street as a holiday rental for, among other things, its ‘Prime City Centre Location’ because of the misleading listing on Booking.com.”,”duration”:”T15S”,”height”:480,”thumbnailUrl”:”https://i.dailymail.com/1s/2026/09/01/16/110979207-0-image-a-17_1788277242552.jpg”,”uploadDate”:”2026-09-01T16:36:34+0100″,”width”:270}

Up Next

Previous Page

Next Page

window.addEventListener(‘metroVideo:relatedVideosCarouselLoaded’, function(data) {
if (typeof(data.detail) === ‘undefined’ || typeof(data.detail.carousel) === ‘undefined’ || typeof(data.detail.carousel.el_) === ‘undefined’) {
return;
}
var player = data.detail.carousel.el_;
var container = player.closest(‘.metro-video-player’);
var placeholder = container.querySelector(‘.metro-video-player__up-next-placeholder’);
if (placeholder) {
container.removeChild(placeholder);
container.classList.add(‘metro-video-player–related-videos-loaded’);
}
});

The consumer champion then added a fake review on 11 August, giving Downing Street a 10/10 ‘exceptional’ rating and including a reference to how enjoyable it was hanging out with Larry The Cat. 

After Which? wrote the review, Booking.com sent a message saying that it would be ‘checked by our team of moderators’, with the review appearing on site ‘almost instantly’.

The listing was eventually removed on 27 August after Which? say they notified the platform several times about the fake listing, six weeks after first being listed. 

‘Glaring gaps’ in security

Which? says their investigation ‘uncovered systemic security failures’ across Booking.com.

For example, Which? say that when they used a separate account to book the seven night stay, they were able to send an email to that account, with a URL link, requesting payment.

Other platforms, such as Airbnb, automatically block this kind of correspondence, blocking external web links, to prevent phishing scams.

And, while Booking.com told Which? they also have the ability to block URLs being sent through the messaging system if it suspects fraudulent activity, it didn’t do so in this case.

Additionally, Which? note that in a previous investigation in 2024, when they created another fake listing, it took Booking.com 18 months to ask for a proof of identity.

This is despite the platform saying they take the process of verifying accommodation listings seriously and there are multiple checks before their listings become bookable.

When Which? did not provide this, the listing was blocked 20 months after it was first set up. 

Rory Boland, Editor of Which? Travel said: ‘If Booking.com’s so-called sophisticated AI systems can’t spot that 10 Downing Street is not a holiday rental, then it’s no wonder scammers can exploit the platform so easily.

‘It would be laughable that we were able to list the UK’s most famous address for rent, if the consequences weren’t so devastating for holidaymakers, who risk losing thousands of pounds to bogus listings and phishing links.’

‘We still haven’t recieved a proper response’

Antony Jewson was scammed after his Booking.com account was hacked.

He found 44 unauthorised transactions on his credit card, totalling almost £4,000, after scammers used his account to book holidays.

‘What concerns me most is how the fraudster was able to use the Booking.com account and payment details without any proper identity checks,’ he says.

Anthony was able to get the money back from the bank but says: ‘We still have not received a proper response, explanation or update on the fraud investigation.

Calls for regulatory action

Under the Online Safety Act, Booking.com is legally required to have measures in place to stop fake listings from being uploaded.

Ofcom, the regulator responsible for enforcing the Act, have yet to act, Which? claim.

Editor Roland Boland said: ‘Booking.com’s checks are clearly unfit for purpose, and the Prime Minister must now urge Ofcom to use the Online Safety Act to crack down on irresponsible online platforms that leave consumers wide open to fraud.’

A spokesperson for Ofcom said: ‘For illegal content generated by users, platforms have existing legal duties that mean they must take it down swiftly once they become aware of it.

‘Booking.com is not in scope of future rules that will apply to paid-for fraudulent advertising, and any change to that would be a matter for Government.’

What do Booking.com say?

A spokesperson for Booking.com said: ‘This limited test is not a true reflection of the experience of millions of listings or reviews published on our platform.

‘The property added by Which? was not visible and ‘live’ for the time period referenced, and as it was not open and bookable, some of our automatic fraud controls were not triggered to completely remove the closed listing.

‘Of the other examples shared by Which?, not all listings have been proven to be fraudulent.

‘We can confirm that we use a range of checks and verification measures to help protect our platform, alongside technologies including artificial intelligence.

‘Together, these measures help us detect and remove the majority of fraudulent listings within 24 hours. We also have tools in place to help protect the integrity of our reviews programme.

‘Fraud affects many industries, and 80% of UK adults believe scams are becoming more sophisticated. We recognise this challenge and continue to strengthen our defences, helping protect our accommodation partners and customers.

‘ This includes tools that limit links in partner-to-guest messages – which have proved effective with professional scammers moving to other channels.

‘There are visible reminders to not click on links customers are not confident about, and booking confirmations also provide further guidance, including details of the agreed payment schedule.

‘Our Help Centre explains how customers can reach our Customer Service team, including local phone numbers.’

Do you have a story you’d like to share? Get in touch by emailing [email protected]


Comment now
Comments

Add Metro as a Preferred Source on Google
Add as preferred source