Which? Lists 10 Downing Street on Booking.com to Expose Flaws
Consumer watchdog Which? successfully listed the UK Prime Minister's residence on Booking.com to expose systemic security failures and fraudulent listing vulnerabilities.
The consumer watchdog Which? exposed systemic security failures on Booking.com by successfully listing 10 Downing Street, the official residence of the UK Prime Minister, as a one-bedroom holiday rental. Researchers created the fake listing on June 18, 2026, using the iconic address and a photo of the black door. The listing remained active until August 27, during which time the platform processed a payment for a week-long stay and allowed a fake review to be published almost immediately.
During the test, researchers used the platform's messaging system to distribute phishing URLs requesting credit card details. In a 20-minute window where the listing was open for requests, 14 people attempted to book the property. Which? noted that hosts are not required to provide proof of ownership for three months after listing, leaving consumers vulnerable to fraud.
Booking.com defended its systems, stating the listing was not live or visible to customers for the entire period, which prevented certain automatic fraud controls from triggering. The company argued the limited test does not reflect the experience of millions of listings on its platform.
Rory Boland, editor of Which? Travel, characterized the platform's checks as unfit for purpose and urged the Office of Communications (Ofcom) to use the Online Safety Act to penalize irresponsible platforms. The Office of Communications (Ofcom) responded that while platforms must swiftly remove illegal user-generated content, Booking.com is not currently in scope for future rules regarding paid-for fraudulent advertising.