Successive politicians have clawed their way past colleagues over the years to call the residence home. Yet in an offer that probably seemed too good to be true, the property site Booking.com has been accused of “systemic security failures” after it was able to set up and accept payment for a fake listing for 10 Downing Street.
A property listed as a “1 bedroom apartment in the heart of London” – with the exact address and a picture of the prime minister’s home – was listed on 18 June by researchers from the consumer watchdog Which?.
The listing, which promised a four-minute walk to the Houses of Parliament, was set up so that users had to request a stay and were unable to reserve and pay automatically.
The booking window opened briefly and closed so that a test could be carried out by a researcher from Which?. The consumer watchdog said a payment for a week-long stay had been processed by the digital travel site that enables users to book hotels and other accommodation as well as flights and car rentals.
The money had still not been refunded more than six weeks after it had been set up, according to Which?, which is associated with the Consumers Association charity.
A fake review was also uploaded to the site, describing the stay as “exceptional” and enjoying the experience of “hanging out with Larry the cat”, in a reference to Downing Street’s resident feline.
Despite Booking.com sending a message saying the review would be checked by a team of moderators, the consumer watchdog said it had been added almost immediately.
The team of researchers were also said to have used Booking.com’s mailing system to send an external URL asking the representative for credit card details to confirm the booking, Which? said.
The watchdog claimed the travel site had told them it had the ability to block URLs being sent through the messaging system if it suspected fraudulent activity, but it had not done so.
The listing was finally removed on 27 August, six weeks after it went live.
Rory Boland, the editor of Which? Travel, said: “If Booking.com’s so-called sophisticated AI systems can’t spot that 10 Downing Street is not a holiday rental, then it’s no wonder scammers can exploit the platform so easily.”
The watchdog said its investigation had “uncovered systemic security failures across the platform” and urged Ofcom, the UK’s communications regulator, to investigate.
A Booking.com spokesperson said: “This limited test is not a true reflection of the experience of millions of listings on our platform. The property added by Which? was not visible to customers or ‘live’ for the time period referenced.
“We use a range of checks, verification measures and artificial intelligence, which help us detect and remove the majority of fraudulent listings within 24 hours.”
It said that as the property was not open and bookable, some of its automatic fraud controls were not triggered to completely remove the fraud listing.
An Ofcom spokesperson said platforms have legal duties obliging them to take down illegal content generated by users once it is known. “Booking.com is not in scope of future rules that will apply to paid-for fraudulent advertising, and any change to that would be a matter for government,” they said.
