A consumer watchdog created a fake Booking.com listing for 10 Downing Street and managed to get far enough through the platform’s systems to take a payment. This is not a sentence written by somebody pitching a British cybersecurity sitcom. Which? used the prime minister’s famous official residence as a test property, complete with photos and a fabricated positive review. The experiment was designed to see how easily scammers could create fraudulent accommodation. The answer appears to be far enough that Larry the cat should check the guestbook.
The Guardian and The Sun reported on the test. Which? created a one-bedroom listing using the exact Downing Street address and recognizable imagery. Researchers briefly opened the property for booking, made a test reservation and processed payment. They also posted a fake glowing review. The listing remained online for weeks before removal. Which? separately tested Booking.com’s messaging protections with an external payment link and said the platform failed to block it. Booking.com disputed aspects of the experiment and said the listing was not fully live to ordinary customers in the way a normal property would be.
That caveat matters. A controlled watchdog test is not the same thing as proof that tourists could routinely book the Cabinet Room for a long weekend. Booking.com says its protections include automated systems and verification measures, and it argues the experiment did not represent normal conditions. Fine. The more basic problem remains awkward. If a system designed to verify accommodation does not immediately become suspicious when someone lists the prime minister’s front door, the threshold for suspicious may need a meeting.
Platforms have spent years telling users that scale requires automation. Millions of listings, messages and payments cannot all be reviewed by humans, so artificial intelligence and automated screening handle the first line of defense. That is reasonable. The 10 Downing Street test is funny because it chooses a property that should be easier for a machine to flag than almost anything else in Britain. The address is globally famous. The building is photographed constantly. It contains a functioning government. If the algorithm needs additional context, perhaps the context window is not the main problem.
Fraud on travel platforms is not funny to people who lose money. Fake listings and phishing messages exploit urgency, unfamiliarity and the fact that travelers are already moving cash through systems they may use only a few times a year. Which? says consumers have reported significant losses and wants tougher oversight. The watchdog’s stunt works because it turns an abstract security concern into a test nobody needs technical training to understand. You should not be able to rent Downing Street. Start there.
Booking.com’s response also illustrates the recurring platform defense that a test did not trigger the right checks because researchers did not behave exactly like real criminals or real hosts. Security researchers hear versions of this constantly. The point of adversarial testing is to behave in ways the system did not expect. Fraudsters are not famous for reading onboarding guidance and following the intended customer journey. A protection that works only when the suspicious person behaves normally has confused etiquette with security.
The fake review is another useful detail. Online marketplaces rely heavily on reviews as trust signals while also fighting fake or manipulated reviews at enormous scale. Publishing a fabricated endorsement of a fabricated apartment at one of the most famous addresses on Earth turns the trust stack into performance art. The review is supposed to reassure the next customer that another human had a good experience. In this case, the human, the stay and the rentable property were all inventions. Five stars for consistency.
Ofcom’s role is complicated because current online-safety rules do not necessarily cover every form of fraudulent user-generated listing in the same way they cover paid advertising. Which? wants regulators and government to close gaps. That is the less amusing part of the story. Platforms move faster than legal categories, and scammers move faster than both. Consumers experience the gap as a missing bank balance while companies and regulators debate which paragraph applies. The incident also shows why obvious test cases are valuable. Sophisticated fraud detection can become obsessed with behavioral patterns, device fingerprints and statistical anomalies while missing semantic absurdity. Humans see the address and laugh immediately. A machine may see properly completed fields. Good verification needs both kinds of intelligence. Otherwise a platform can become extremely advanced at checking whether the impossible listing was submitted in the correct format.
The correct lesson is not that Booking.com is uniquely incompetent. Any marketplace operating at global scale faces relentless fraud attempts. The lesson is that claims about sophisticated verification should be tested against stupidly obvious cases as well as sophisticated attacks. A system can catch a thousand subtle anomalies and still deserve ridicule if Number 10 appears as a one-bedroom getaway with an exceptional review.
Which? chose Downing Street because everyone would recognize the absurdity. That is what makes the result useful. Digital platforms increasingly ask consumers to trust invisible verification systems they cannot inspect. A famous black door became the rare test case where the public can evaluate the output without needing a cybersecurity degree. The machine was given the prime minister’s address. It still needed more clues.
If a travel platform’s verification system needs more evidence before deciding that 10 Downing Street probably is not a holiday rental, what happens when the fake address is somewhere nobody recognizes?
Sources
The Guardian: Fake 10 Downing Street listing on Booking.com highlights security failures
The Sun: Watchdog set up fake Booking.com listing for the PM’s home to highlight holiday scammers





