You are viewing 1 of your 2 free articles
Booking.com’s fraud and security protocols have been criticised after consumer champion Which? successfully created and processed payments for a fake listing of 10 Downing Street.
An investigation by Which? Travel revealed that researchers set up the fake property – headlined ‘1 bedroom apartment in the heart of London’ using the address and photograph of the Prime Minister’s residence – in a matter of minutes on June 18.
Booking.com has pushed back against the findings, maintaining the test was “not a true reflection” of its platform and arguing that automatic fraud controls were not triggered because the listing was not kept continuously open and bookable.
During a brief 20-minute window, 14 people inquired about staying at the property. Booking.com subsequently processed a payment from a Which? researcher for a week-long stay, with the funds remaining unrefunded more than six weeks later.
Which? said it was also able to publish a fraudulent 10/10 review mentioning “Larry The Cat”, which went live almost immediately, and used the platform’s internal messaging system to send external payment links to test accounts without automatic interception.
Under current Booking.com policy, hosts are not required to provide photo ID or proof of ownership until three months after a listing goes live. The fake page was only removed on August 27 after Which? issued a final right of reply.
Rory Boland, editor of Which? Travel, said: “If Booking.com’s so-called sophisticated AI systems can’t spot that 10 Downing Street is not a holiday rental, then it’s no wonder scammers can exploit the platform so easily.
“It would be laughable that we were able to list the UK’s most famous address for rent, if the consequences weren’t so devastating for holidaymakers, who risk losing thousands of pounds to bogus listings and phishing links.”
Which? is urging regulator Ofcom to investigate the online travel agent’s compliance under the Online Safety Act, which legally requires platforms to mitigate against fake listings and remove fraudulent content swiftly.
A spokesperson for Booking.com defended the platform’s security setup and disputed the methodology.
“This limited test is not a true reflection of the experience of millions of listings or reviews published on our platform,” the spokesperson said.
“The property added by Which? was not visible and ‘live’ for the time period referenced, and as it was not open and bookable, some of our automatic fraud controls were not triggered to completely remove the closed listing.
“We can confirm that we use a range of checks and verification measures to help protect our platform, alongside technologies including artificial intelligence. Together, these measures help us detect and remove the majority of fraudulent listings within 24 hours.”
An Ofcom spokesperson stated that platforms currently have legal duties to take down illegal user-generated content swiftly once notified, but added that Booking.com is “not in scope of future rules that will apply to paid-for fraudulent advertising”.