One of Europe’s leading consumer watchdogs was able to list 10 Downing Street as a holiday rental on booking.com and accept payments from people keen to stay in the UK prime minister’s home.

Which? Travel said the exercise exposed “glaring gaps” in the online portal’s security despite its claims that it uses advanced AI and multiple security controls to combat fraudulent listings.

The magazine said it set up the fake listing in minutes and noted that under booking.com’s own policies, hosts are not required to provide photo ID or proof of ownership until three months after a listing goes live.

A researcher working for the magazine listed a property on the platform on June 18th under the heading “1 bedroom apartment in the heart of London”. They included the exact address and a photograph of 10 Downing Street.

The listing was set so users had to request a stay – so nobody could book automatically without being approved.

The Which? Travel team opened the booking window briefly to allow a representative to perform a test booking. While the booking window was open, 14 people got in touch to ask if they could stay in Downing Street.

Booking.com also processed a payment from a Which? researcher for a weeklong stay in Downing Street, with the magazine saying the money had still not been refunded.

The listing was not removed until August 27th and the consumer watchdog also followed up with a fake review on August 10th rating 10 Downing Street as a 10- out-of-10 property and declaring it to be an “exceptional” option for would-be visitors.

Booking.com’s systems said the review would be “checked by our team of moderators” but it appeared almost immediately despite being a joke and including a reference to how enjoyable it was hanging out with “Larry the cat”.

Booking.com users struggle in the face of phantom bookings and rogue cancellations

“If Booking.com’s so-called sophisticated AI systems can’t spot that 10 Downing Street is not a holiday rental, then it’s no wonder scammers can exploit the platform so easily,” said Which? Travel editor Rory Boland.

“It would be laughable that we were able to list the UK’s most famous address for rent, if the consequences weren’t so devastating for holidaymakers, who risk losing thousands of pounds to bogus listings and phishing links.”

A spokeswoman for booking.com told The Irish Times that the “limited test does not reflect the experience of millions of listings and reviews on our platform”.

She said the property added by Which? “was not ‘live’ or visible to customers during the period referenced, and, as the property was closed, some automatic fraud controls were not triggered”.

Booking.com uses “a range of checks, verification measures and AI-powered technologies to protect our platform, detecting and removing most fraudulent listings within 24 hours. We also have tools in place to help protect the integrity of our reviews programme,” she added.

The spokeswoman said booking.com was continuing to strengthen “protections for accommodation partners and customers as scams become more sophisticated”.