Imagine booking a holiday stay at 10 Downing Street—the official residence of the British Prime Minister—and leaving a review about hanging out with Larry the cat. A UK consumer group recently did just that to reveal major verification flaws on the travel website Booking.com.
The consumer watchdog Which? created the fake listing to test the platform's security. Researchers were able to list the famous address, request a booking, and leave a humorous review. The property stayed on the platform for two months before Booking.com finally removed it on August 27.
During a brief 20-minute window when researchers opened the listing, 14 unsuspecting people attempted to book a stay. Which? researchers also tested sending an external payment link through Booking.com's internal messaging service. The system failed to block or flag the link, highlighting a vulnerability that scammers often use to steal money from travellers.
Rory Boland, the travel editor at Which?, warned that these security failures put holidaymakers at risk of losing thousands of pounds to fake listings and phishing scams. He argued that if automated safety tools cannot identify the UK's most famous home, the platform's checks are inadequate.
Booking.com defended its safety record, stating that the test did not reflect normal user experiences because the listing was kept closed for most of the time. The company explained that its automated fraud controls rely on artificial intelligence (AI) to detect and remove most fraudulent listings within 24 hours, and reminded customers to be careful when clicking external links.