Fake 10 Downing Street listing exposes dangerous fraud failings at Booking.com, Which? reveals
Despite Booking.com claiming to use advanced AI and multiple security controls, Which? Travel set up the fake listing for the world-famous building in minutes. Under Booking.com’s own policies, hosts are not required to provide photo ID or proof of ownership until three months after a listing goes live.
Which? has repeatedly exposed Booking.com’s security gaps and had endless reports from consumers with dozens of complaints of receiving scam messages on the platform and hundreds of people arriving at properties to discover that the listing was fake. To make matters worse, when customers have tried to contact Booking.com for help, they are initially directed to an ineffective AI chatbot.
The latest Which? Travel investigation uncovered systemic security failures across the platform. On 18 June, a Which? researcher listed a property on Booking.com, headlined '1 bedroom apartment in the heart of London,' including the exact address and a photo of the most famous front door in Britain, 10 Downing Street.
The listing was set so users had to request a stay - so nobody could book automatically without being approved. The Which? Travel team opened the booking window very briefly so a Which? representative could do a test booking, and then it was closed again. Within this time, 14 people got in touch to ask if they could stay at the Prime Minister's home.
Booking.com processed a payment from a Which? researcher using a different account for a week-long stay at the fake listing. The money has still not been refunded, more than six weeks after it was set up.
The consumer champion then added a fake review on 11 August, giving it 10/10 - ‘exceptional’. After writing the review Booking.com sent a message saying that it would be ‘checked by our team of moderators’ - but the review appeared almost immediately despite obviously being a joke, including a reference to how enjoyable it was hanging out with Larry The Cat.
Despite only setting themselves up as a host that same day and the listing being an obvious fake, the Which? Travel team were able to use Booking.com’s own mailing system to send an external URL asking the Which? representative from the other account to enter credit card details to confirm the booking. While competitors like Airbnb automatically block external web links in messages to protect users from phishing scams, Booking.com failed to intercept the link.
Booking.com told Which? that it has the ability to block URLs being sent through the messaging system, if it suspects fraudulent activity. But it didn’t do so in this case.
The listing was not removed until August 27, after Which? had given Booking.com a final opportunity to comment on the investigation.
When Which? previously investigated Booking.com in October 2024, the consumer champion was able to create a fake listing within 15 minutes. It took a full 18 months until Booking.com asked for a proof of identity, despite the platform saying they take the process of verifying accommodation listings seriously and there are multiple checks before their listings become bookable. When Which? did not provide this, the listing was finally blocked – 20 months after it was first set up.
Under the Online Safety Act Booking.com is legally required to have measures in place to mitigate against consumers encountering fake listings in the first place. For any listings that make it through, Booking.com has to act swiftly to remove them when it becomes aware of them. It certainly shouldn't be waiting two months to take action.
Yet despite Which? investigations uncovering countless examples of fraud over the past year, Ofcom, the regulator responsible for enforcing the Act, has done nothing to hold it to account. Ofcom must launch an urgent investigation into Booking.com's compliance and take robust action to stop the platform from continuing to break the rules.
The Prime Minister has an opportunity to reset expectations when it comes to the urgency of protecting consumers from online scams and show he won’t let tech companies off the hook for failing to protect their users.
Rory Boland, Editor of Which? Travel said:
“If Booking.com's so-called sophisticated AI systems can't spot that 10 Downing Street is not a holiday rental, then it's no wonder scammers can exploit the platform so easily. It would be laughable that we were able to list the UK’s most famous address for rent, if the consequences weren't so devastating for holidaymakers, who risk losing thousands of pounds to bogus listings and phishing links.
“Booking.com’s checks are clearly unfit for purpose, and the Prime Minister must now urge Ofcom to use the Online Safety Act to crack down on irresponsible online platforms that leave consumers wide open to fraud.”
ENDS
Notes to Editors
A spokesperson for Booking.com said:
"This limited test is not a true reflection of the experience of millions of listings or reviews published on our platform.
“The property added by Which? was not visible and ‘live’ for the time period referenced*, and as it was not open and bookable, some of our automatic fraud controls were not triggered to completely remove the closed listing.
“Of the other examples shared by Which?, not all listings have been proven to be fraudulent.
“We can confirm that we use a range of checks and verification measures to help protect our platform, alongside technologies including artificial intelligence. Together, these measures help us detect and remove the majority of fraudulent listings within 24 hours. We also have tools in place to help protect the integrity of our reviews programme.
“Fraud affects many industries, and 80% of UK adults believe scams are becoming more sophisticated. We recognise this challenge and continue to strengthen our defences, helping protect our accommodation partners and customers. This includes tools that limit links in partner-to-guest messages - which have proved effective with professional scammers moving to other channels.
“There are visible reminders to not click on links customers are not confident about, and booking confirmations also provide further guidance, including details of the agreed payment schedule. Our Help Centre explains how customers can reach our Customer Service team, including local phone numbers."
*By ‘time period referenced’ Booking.com is referring to the two months in which the listing was online. It was open and bookable initially, but Which? then made sure that it could not be booked by genuine customers. .*
A spokesperson for Ofcom said:
“For illegal content generated by users, platforms have existing legal duties that mean they must take it down swiftly once they become aware of it.
“Booking.com is not in scope of future rules that will apply to paid-for fraudulent advertising, and any change to that would be a matter for Government.”
ENDS
Methodology
On 18 June, Which? Travel listed a property on Booking.com, headlined '1 bedroom apartment in the heart of London', prominently listed as '10 Downing Street, London' alongside a photo of the most famous front door in Britain. Just four minutes on foot to the Houses of Parliament, it promised.
The listing was set up by Which? Travel's editor. It was set so that users had to request a stay - so nobody could book automatically without being approved.
The consumer champion opened the booking window very briefly so that a Which? representative could do a test booking, and then it was closed again (14 people got in touch during those 20 minutes to ask if they could stay).
Which?’s representative did a test booking for the end of July and gave it a 10/10 review on 11 August.
The listing was finally removed on 27 August after Which? notified the platform several times about the fake listing, six weeks after first being listed.
Screengrabs of the property listed on Booking.com and video of listing

Case studies
Antony Jewson was hit by 44 unauthorised transactions on a credit card—totalling almost £4,000—after his Booking.com account was hacked.
He said: "What concerns me most, is how the fraudster was able to use the Booking.com account and payment details without any proper identity checks." He was able to get the money back from the bank but says: "We still have not received a proper response, explanation or update on the fraud investigation."
Another user, says he resorted to watching YouTube videos called things like How to contact Booking.com, after finding it impossible to speak with a human being. He and his friend had spent more than £900 on a listing that appeared no longer to exist—and then on last-minute hotel rooms. Booking.com refunded John Dickson £208 following Which? contact—although he's still out of pocket for his expenses.
Booking.com says they are investigating this case study's issue.
Useful links
The scam crisis on Booking.com
Booking.com replaces customer service staff with AI
About Which?
Which? is the UK’s consumer champion, empowering people to make confident choices and demand better. Through our research, investigations and product testing, we provide trusted insight and expert recommendations on the issues that matter most to consumers.
Fiercely independent, we put people over profit - shining a light on unfair practices, influencing policy and holding businesses to account to make life simpler, fairer and safer for everyone.
The information in this press release is for editorial use by journalists and media outlets only. Any business seeking to reproduce information in this release should contact the Which? Endorsement Scheme team at endorsementscheme@which.co.uk.
