Booking.com Security Flaw Exposed After 10 Downing Street Listed as Rental

by priyanka.patel tech editor
Booking.com Security Flaw Exposed After 10 Downing Street Listed as Rental

Consumer watchdogs revealed glaring security gaps on Booking.com after successfully listing 10 Downing Street as a holiday rental. The stunt exposed vulnerabilities in platform verification and highlighted how easily scammers can exploit multi-billion-dollar booking systems without triggering automatic fraud controls.

The UK consumer watchdog Which? Travel tested online travel giant Booking.com by setting up a fraudulent listing for the official London residence of the prime minister. Researchers published the advertisement under the title 1 bedroom apartment in the heart of London on June 18th. The listing featured the exact address alongside a photograph of Britain’s most famous front door, promising a location just four minutes on foot from the Houses of Parliament.

Despite the absurdity of offering the prime minister’s flat for short-term stays, the platform published the listing without demanding photo ID or any proof of property ownership. Under Booking.com’s existing policies, hosts are not required to provide identity verification until three months after a listing goes live, creating a massive window for potential fraud.

High Demand and Unchecked Payments on Booking.com

The bogus advertisement drew immediate interest from prospective travelers who remained unaware of the landmark’s true identity. Although researchers configured the listing so that guests had to request a stay rather than book automatically, 14 people inquired about availability during a brief 20-minute window. Furthermore, the platform processed a payment from a researcher for a weeklong stay at the prime minister’s address.

The consumer watchdog also tested the platform’s review moderation by posting a 10-out-of-10 rating on August 10th. The review declared the property an exceptional option for visitors, with resident mouser Larry the cat as a highlight. Although Booking.com’s system stated the review would be checked by moderators, it appeared almost immediately. The listing remained active on the site until August 27th, while the fraudulent booking was not officially cancelled until August 31st.

Platform Defenses and Regulatory Context

In response to the investigation, a company spokesperson defended the platform’s overall security measures while noting the unique nature of the test.

Larry the cat outside 10 Downing Street. A spokeswoman for booking.com said the ‘limited test does not reflect the
Photo: irishtimes.com

A Booking.com spokesperson stated, via BBC, that this limited test was not a true reflection of the experience of millions of listings or reviews published on their platform.

The company explained that because the property was closed and not actively visible to the public during most of the two-month period, some automatic fraud controls failed to trigger a complete removal. Representatives emphasized that the portal relies on automated tools and a range of checks and verification measures to detect most fraudulent listings within 24 hours.

Industry observers note that mandatory identity checks introduced across the sector stem largely from tax compliance regulations rather than direct anti-fraud mandates. Legal requirements enacted in 2024, known as the Platform Operators (Due Diligence and Reporting Requirements) Regulations, primarily ensure that holiday accommodation owners report their earnings to tax authorities, with consumer protection acting as an indirect benefit.

Criticism Over Messaging Risks and Phishing Scams

Beyond phantom properties, consumer advocates point to ongoing vulnerabilities involving the platform’s internal messaging system. Scammers routinely send external links to travelers via direct messages, directing users to phishing sites designed to steal credit card details.

10 Downing Street. The black door featuring the "10" lettering and letterbox is closed, with Larry the Cat sat on the
Photo: bbc.co.uk

During the test, researchers successfully used Booking.com’s own mailing system to transmit an external URL requesting payment details to confirm a reservation, proving that bad actors face few immediate barriers when targeting consumers.

Industry Fallout and Expert Warnings

The ability to monetize a fake listing at the United Kingdom’s most famous address underscores the financial risks ordinary holidaymakers face when booking online travel. Consumer representatives argue that current automated defenses remain inadequate against determined fraudsters.

Rory Boland, Which? Travel editor, asserted that if Booking.com’s so-called sophisticated AI systems could not spot that 10 Downing Street was not a holiday rental, then it was no wonder scammers could exploit the platform so easily.

Boland added that it would be laughable that we were able to list the UK’s most famous address for rent, if the consequences weren’t so devastating for holidaymakers, who risk losing thousands of pounds to bogus listings and phishing links.

Unresolved Financial Questions

Questions also remain regarding the return of funds collected during the test. Although Booking.com initiated a cancellation process, the consumer group noted uncertainty over whether the platform would retain a commission fee or service charge from the phoney transaction, meaning the company potentially earned revenue from a fraudulent booking at the prime minister’s home.

The Fake Number 10 Downing Street!

You may also like