Imagine scrolling through rental listings and finding the British Prime Minister's official residence available for a week-long stay. Sounds ridiculous, right? Yet that's exactly what happened when researchers at consumer watchdog Which? decided to test the security of one of the world's largest accommodation platforms. The results were not reassuring.

On June 18th, Which? Travel uploaded a fake listing presenting 10 Downing Street as a cozy one-bedroom apartment in central London. They used the actual government address, a photo of the building's iconic black front door, and a description boasting about its "prime city-centre location" and convenient four-minute walk to Parliament. Within minutes, the listing went live. Within hours, real travelers started requesting to book it.

Booking.com listing interface showing a fake 10 Downing Street holiday rental
The fake Booking.com listing for 10 Downing Street that was created to expose security vulnerabilities

How Quickly the Scam Took Shape

The researchers deliberately set the property to require booking requests rather than allowing instant reservations. They then cracked open a 20-minute window for one of their team members to place a test booking. During that brief window, 14 actual people tried to inquire about staying at the supposed residence. The booking was accepted. Booking.com processed payment. As of the time of the investigation, that money had not been refunded six weeks later.

But the problems didn't stop at the initial fraud. Which? also tested how the platform handles reviews and messaging. On August 11th, they submitted a fake five-star review raving about their "exceptional" stay and mentioning "hanging out with Larry the cat" (a reference to the famous Downing Street cat). Despite Booking.com's claim that reviews undergo moderation, the fake review appeared almost instantly and remained visible.

Booking.com listing for 10 Downing Street displayed on laptop screen
The fake 10 Downing Street listing on Booking.com that exposed security vulnerabilities in the platform's verification process

The researchers went further, using Booking.com's internal messaging system to send a suspicious external link requesting payment confirmation. Shockingly, Booking.com did not block it. This is particularly damning because the company had previously told Which? that it could restrict URLs in messages when fraud is suspected. The fake listing stayed online for nearly six weeks before finally being removed on August 27th.

What This Means for Travelers

The investigation uncovered what Which? called "systemic security failures." Under Booking.com's own policies, hosts aren't required to provide photo ID or proof of property ownership until three months after a listing goes live. That's a dangerously wide window for bad actors. Travelers booking vacation rentals assume basic protections are in place. This experiment suggests those protections are weaker than many realize.

Rory Boland, editor of Which? Travel, pulled no punches: "If Booking.com's so-called sophisticated AI systems can't spot that 10 Downing Street is not a holiday rental, then it's no wonder scammers can exploit the platform so easily." He warned that the consequences for vacationers could be severe, with travelers potentially losing thousands of pounds to fraudulent listings and phishing links. Young travelers especially may be at risk, as they rely heavily on online platforms for accommodation decisions.

Booking.com disputed the findings, arguing that the test was not representative of typical listings and that the fake property was never truly "live" or visible to customers in the way the report suggested. The company maintains it uses AI and verification measures to catch and remove most fraudulent listings within 24 hours. They contended that certain automatic controls didn't trigger because the fake property wasn't continuously open for booking.

Which? called on Ofcom to investigate Booking.com's compliance with the Online Safety Act, arguing that the platform has left consumers vulnerable to fraud. Ofcom responded that platforms have existing legal duties to remove illegal content quickly once alerted, but noted that oversight of online platforms remains a contentious issue. The agency added that Booking.com is not currently in scope for upcoming rules about paid-for fraudulent advertising.

For travelers planning getaways, the takeaway is clear: trust platform security measures, but verify independently. Before booking any rental, especially through major platforms, confirm the property details independently, research the host's history thoroughly, and use credit cards (never debit) for protection. The digital infrastructure connecting you to your vacation spot may be more fragile than you thought.