Newsclip — Social News Discovery

Business

How a Fake 10 Downing Street Listing Exposed Booking.com's Weak Security

September 1, 2026
  • #Onlinesafety
  • #Bookingcom
  • #Travelscams
  • #Consumerprotection
  • #Technews
  • #Cybercrime
1 view•0 comments
How a Fake 10 Downing Street Listing Exposed Booking.com's Weak Security

Booking.com's Fraud Gap: A Fake Listing That Shouldn't Have Passed

When Which? set out to test Booking.com's fraud prevention systems, they didn't expect to find such a glaring loophole. They uploaded a fake listing for 10 Downing Street — the official residence of the UK Prime Minister — and somehow it made its way through their verification process.

The listing was a parody: an ad for a '1 bedroom apartment in the heart of London', complete with images of the iconic front door, describing it as a 'prime city centre location' just 400 meters from Big Ben. It also included a fictional review that mentioned 'hanging out' with Larry the cat — a nod to the real-life mouser who is said to keep the premises pest-free.

Yet despite these obvious signs, Booking.com did not remove the listing until two months later, when it was finally taken down on August 27th. And even then, it only happened after Which? made a public inquiry and highlighted its presence on the site.

'This limited test is not a true reflection of the experience of millions of listings or reviews published on our platform,' said a Booking.com spokesperson in response to the report.

While the company cited its automated fraud controls as being in place, they were apparently ineffective in flagging this particular listing. The site only activated these checks after a manual review — and even then, it took weeks to remove the fake content.

What This Means for Travelers

For users like myself, who've used Booking.com over the years, the implications are troubling. If someone can list 10 Downing Street as a vacation rental — a property that doesn't exist as a private accommodation — it's hard to believe that legitimate scammers won't find similar loopholes.

What's more alarming is that the fake listing was active for only 20 minutes, during which time Which? researchers were able to collect data from interested parties. Out of those 14 people who tried to book the property, only one was a known researcher, yet they still managed to get the system to accept their request.

And that's not all — Which? reported that Booking.com allowed them to send messages containing links to external payment sites, which should have been blocked by standard security protocols. These are the kinds of red flags that usually trigger warnings on reputable booking platforms, but in this case, they were ignored.

The Human Element and AI Missteps

Booking.com's own representatives say their AI tools help detect fraudulent listings within 24 hours. But in reality, it seems like these systems are still falling short — especially when dealing with well-known public figures or iconic locations.

Rory Boland, Travel Editor at Which?, wasn't impressed by what he saw: If Booking.com's so-called sophisticated AI systems can't spot that 10 Downing Street is not a holiday rental, then it's no wonder scammers can exploit the platform so easily.

It's worth noting that AI alone isn't enough to prevent fraud. There needs to be a combination of real-time monitoring, robust human oversight, and rapid response mechanisms. And clearly, Booking.com is not yet delivering on all fronts.

A Broader Problem in Online Safety

This incident also points to a larger issue within the online travel industry — specifically, how companies like Booking.com are held accountable for the content they host. The UK's Online Safety Bill (OSA) places responsibility on platforms to act swiftly upon identifying illegal or harmful content, but enforcement is inconsistent.

Ofcom, the regulatory body responsible for enforcing the OSA, told Which? that platforms have existing legal duties that mean they must take it down swiftly once they become aware of it. But when platforms fail to act quickly enough, users end up footing the bill — both financially and emotionally.

According to a recent study by the UK's National Cyber Security Centre (NCSC), over 80% of adults believe scams are becoming more sophisticated. That means companies like Booking.com must evolve their security systems accordingly — or risk losing public trust entirely.

Why This Matters Beyond the Travel Industry

The fake 10 Downing Street listing isn't just about hotels and bookings; it's a symbol of how easily digital platforms can be manipulated. In our increasingly connected world, where people rely on online reviews and third-party vendors for everything from accommodation to food delivery, platforms must take responsibility for maintaining trust.

This is particularly true in cases like this one, where the content is so obviously absurd — yet still made its way onto the site. It raises serious questions about how vulnerable people are when it comes to protecting themselves online.

As someone who has traveled extensively using platforms like Booking.com, I know firsthand how convenient they can be. But now, I'm questioning whether that convenience comes at too high a cost — especially when user safety is compromised.

What Should Happen Next?

Which? has called for stronger enforcement of the Online Safety Act to ensure platforms like Booking.com are held accountable for removing false or fraudulent content immediately. This isn't just about one listing — it's about establishing accountability across the board.

For Booking.com, this is a wake-up call. Their current fraud detection systems need to be re-evaluated and updated, especially considering that public figures, landmarks, and institutions should be protected from exploitation by scammers.

At the same time, travelers must remain vigilant. While these incidents are rare, they do happen — and when they do, it's essential to know how to identify potential fraud early on. That means double-checking addresses, avoiding suspicious links, and reporting any questionable listings immediately.

In short, we all have a role to play in ensuring online safety remains a priority. And until platforms like Booking.com start taking these issues seriously, the risk of falling victim to scams will continue to rise.

Key Facts

  • Primary Entity: Booking.com
  • Fake Listing Location: 10 Downing Street
  • Test Conducted By: Which?
  • Listing Removal Date: 27 August 2026
  • Listing Duration: 20 minutes
  • Fake Review Mentioned: Larry the cat
  • Booking.com Response Time: Two months
  • Booking.com AI Claim: Detect and remove fraudulent listings within 24 hours

Background

Consumer watchdog Which? tested Booking.com's fraud prevention systems by creating a fake listing for 10 Downing Street, the official residence of the UK Prime Minister. The listing included images of the iconic front door, described it as a 'prime city centre location', and featured a fictional review mentioning Larry the cat. Despite obvious signs of falsity, the listing remained active for two months until Which? publicly highlighted it. Booking.com claimed its automated fraud controls were ineffective and only activated after manual review.

Quick Answers

What fake listing was created on Booking.com?
Booking.com was used to create a fake listing for 10 Downing Street, the official residence of the UK Prime Minister.
When was the fake listing removed from Booking.com?
The fake listing was removed from Booking.com on 27 August 2026.
Who conducted the test of Booking.com's fraud detection?
Which? conducted the test of Booking.com's fraud detection systems.
How long was the fake listing active on Booking.com?
The fake listing was active for 20 minutes during which time Which? researchers collected data from interested parties.
What was the response from Booking.com regarding the fake listing?
Booking.com said its automatic fraud controls were not triggered because the listing was not 'live' on its site across the two months it was present.
What did Which? say about Booking.com's AI fraud detection?
Which? Travel editor Rory Boland said Booking.com's AI fraud detection systems were 'unfit for purpose'.
Did Booking.com allow external links in the fake listing?
Booking.com allowed Which? to send messages containing links to external payment sites, which should have been blocked by standard security protocols.
How many people tried to book the fake 10 Downing Street property?
Fourteen people tried to book the fake 10 Downing Street property during the 20-minute window.

Frequently Asked Questions

What was the fake listing about on Booking.com?

The fake listing advertised a '1 bedroom apartment in the heart of London' at 10 Downing Street, complete with images of the iconic front door and a description as 'a prime city centre location'.

What did the fake review say about 10 Downing Street?

The fake review mentioned 'hanging out' with Larry the cat, referencing the real-life mouser who reportedly keeps the premises pest-free.

How long did Booking.com take to remove the fake listing?

Booking.com took two months to remove the fake listing after Which? highlighted it publicly on the site.

What did Booking.com claim about its fraud controls?

Booking.com claimed that a range of checks and verification measures help secure the site, and that technologies such as AI help detect and remove the majority of fraudulent listings within 24 hours.

Did Booking.com's systems flag the fake listing?

No, Booking.com's fraud detection systems did not flag the fake listing until two months later after Which? made a public inquiry.

What was the outcome of the booking attempts for the fake property?

Only one booking request from a person known to be a Which? researcher was accepted, despite 14 people attempting to book the property during the 20-minute window.

Source reference: https://www.bbc.co.uk/news/articles/cly4e0wn452o

Comments

Sign in to leave a comment

Sign In

Loading comments...

More from Business