White hat hackers post UK prime minister’s residence on Booking.com – and people actually try to book it
More than a dozen travelers tried to book 10 Downing Street within the first half hour, while Booking.com even accepted a fake 10/10 review mentioning the "Larry the Cat." .

10 Downing Street, the official residence of the UK prime minister. Ryan Jenkinson/Getty Images
- Researchers listed 10 Downing Street on Booking.com and successfully processed a real payment.
- At least 14 people inquired within 20 minutes, when booking requests were open.
- A fake 10/10 review appeared almost immediately despite Booking.com saying it would be moderated.
- Booking.com disputed the test’s relevance and said it uses checks, artificial intelligence, and fraud controls.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
White hat hackers successfully listed the UK prime minister’s residence on Booking.com – and more than a dozen travelers tried to book it within minutes.
Researchers at the UK non-profit consumer group WHICH? wanted to prove how easy it is to post fake rental listings on sites like Booking.com and scam unsuspecting travelers out of their money.
"1 bedroom apartment in the heart of London"
To create the ultimate test, the researchers chose to use the widely recognized UK address 10 Downing Street – otherwise known as the official residence and office of the UK prime minister.
They created a fake Booking.com listing using the address complete with pictures, a fake property description, and messaging links that could be used to send phishing requests.
The “1 bedroom apartment in the heart of London” – advertised as the entire place at 215 square meters – was listed by Which? Travel on June 19th.
The ad was “prominently listed as '10 Downing Street, London' alongside a photo of the most famous front door in Britain. Just four minutes on foot to the Houses of Parliament,” the researchers said.
Although automatic booking was turned off for the listing, at least 14 inquiries were sent to the consumer advocates through the app during the initial 20-minute testing window.
What’s more, Which? says that Booking.com actually processed at least one payment made by the researchers using a different account for a week-long stay – and that money had still not been refunded as of August.
Also concerning, the researchers decided to leave a fake review for their 10 Downing Street listing on August 11th, “giving it 10/10 - ‘exceptional’,” although no one had booked or stayed at the listing.
After writing the review, Which? said they received an email stating that Booking.com moderators would check the fake review, even though it was posted under the listing right away.
The review appeared almost immediately despite obviously being a joke, including a reference to how enjoyable it was hanging out with Larry The Cat.said Which? Travel.
Fake listing opens door to phishing
One of the biggest lessons learned from the experiment was how quickly scammers could get access to someone's credit card account numbers and other sensitive personal information.
The researchers said, despite the fact that the Which? host account was created that same day with an “obviously fake” listing, Booking.com allowed them to use the platform’s messaging system to send an external link asking for credit card details to confirm the booking.
Which? noted that most platforms, including Airbnb, automatically block messages containing suspicious links to protect users from phishing scams, but that Booking.com, which says it also has that ability, “failed to intercept the link.”
The listing was finally removed on 27 August after Which? notified the platform several times about the fake listing, six weeks after first being listed,Which? Travel said.
That could be considered light speed after the group's last Booking.com experiment.
In October 2024, Which? also created a fake listing which apparently took more than a year and a half to get removed from the Booking.com site.
Booking.com responds
Booking.com, not surprisingly, pushed back on the findings, saying the experiment was not representative of the millions of listings and reviews on its platform, and that some automatic fraud controls were not triggered because the listing was later closed to genuine customers.
We can confirm that we use a range of checks and verification measures to help protect our platform, alongside technologies including artificial intelligence,Booking.com said.
The company added that its use of AI tools helps it remove the majority of fraudulent listings within 24 hours and that it continues to strengthen protections around reviews and suspicious links in messages.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.