< Back to all clusters
[BUSINESS] · United Kingdom · 8 sources

started · updated

Booking.com security flaws exposed by fake 10 Downing Street listing

The UK consumer watchdog Which? has exposed security vulnerabilities on Booking.com after successfully creating a fraudulent listing for 10 Downing Street, the official residence of the British Prime Minister.

Researchers uploaded the fake advertisement on June 18, describing it as a ‘1 bedroom apartment in the heart of London’ and using images of the iconic front door. The listing remained active for two months before being removed. During a brief 20-minute window where the listing was made visible to the public, 14 people inquired about availability, and the platform processed a payment from a researcher for a weeklong stay.

Which? criticized the platform’s verification processes, noting that Booking.com does not require identity verification from hosts until three months after a listing goes live. The watchdog also noted that a fake review mentioning the resident cat, Larry, was published almost immediately without effective moderation.

A Booking.com spokesperson stated that because the listing was not ‘live’ across the entire site during the testing period, certain automatic fraud controls were not triggered. The company maintained that it uses AI and various verification measures to detect and remove the majority of fraudulent listings within 24 hours.

Entities

10 Downing Street · Booking.com · Which?