Over the years, various politicians have inhabited the iconic residence at 10 Downing Street. However, in a surprising turn of events, the accommodation booking platform Booking.com has faced serious allegations of “systemic security failures” following its ability to establish and process payments for a fraudulent listing of the Prime Minister’s residence.
On June 18, researchers from the consumer advocacy group Which? discovered a listing for a “1 bedroom apartment in the heart of London,” which included the precise address and an image of 10 Downing Street. The listing touted its proximity to the Houses of Parliament, claiming it was only a four-minute walk away.
This particular listing required users to submit a request for a stay rather than allowing direct reservations and payments. In a brief window of availability, researchers conducted a test, during which a payment for a week-long booking was successfully processed by the digital travel platform, which facilitates hotel reservations, flights, and car rentals.
According to Which?, the payment had not been refunded more than six weeks after the listing was created, and the organization is affiliated with the Consumers Association charity.
Additionally, a fabricated review was posted on the site, praising the experience as “exceptional” and mentioning enjoyment from “hanging out with Larry the cat,” a nod to the resident cat of Downing Street.
Although Booking.com communicated that the review would be scrutinized by a team of moderators, Which? reported that it appeared almost immediately after being submitted. The researchers also allegedly utilized Booking.com’s messaging system to send an external link requesting credit card information for booking confirmation.
The consumer organization asserted that Booking.com had previously indicated it was capable of blocking URLs sent through its messaging system if fraudulent activity was suspected, yet this safeguard did not activate in this instance.
After being live for six weeks, the misleading listing was finally removed on August 27. Rory Boland, the editor of Which? Travel, commented, “If Booking.com’s so-called advanced AI systems can’t recognize that 10 Downing Street is not a vacation rental, it’s understandable that scammers can easily take advantage of the platform.”
The investigation by Which? revealed significant security vulnerabilities within the platform, prompting the organization to call on Ofcom, the UK’s communications regulator, to conduct an inquiry.
A spokesperson for Booking.com responded, stating, “This limited test does not accurately represent the experience of millions of listings on our platform. The property added by Which? was not visible to customers or operational during the referenced time period.”
The representative further explained that the company employs various verification measures and artificial intelligence tools to identify and eliminate most fraudulent listings within a day. However, since the property was not active and available for booking, some automated fraud detection mechanisms were not fully engaged to remove the fraudulent listing.
An Ofcom spokesperson emphasized that platforms are legally required to remove any illegal user-generated content once they become aware of it. “Booking.com does not fall under the future regulations concerning paid fraudulent advertising, and any changes to this would need to be addressed by the government,” they stated.

















