A consumer watchdog called Which? conducted an investigation by creating a fake hotel listing for 10 Downing Street, the official residence of the UK Prime Minister, on the online booking platform Booking.com. The experiment exposed serious security flaws on the platform. The fake listing, which included the correct address, a photo of the property, and a description mentioning a short walk to the Houses of Parliament, was created and made visible "within minutes." The listing required users to request a stay rather than book automatically, and it was briefly open for a test booking before being closed again. Which? reported that Booking.com processed a payment for a week-long stay from one of its researchers. More than six weeks later, the funds had not been returned. A fake review was also posted, praising the experience and mentioning "hanging out with Larry The Cat," a well-known cat associated with the Prime Minister’s residence. Despite the company stating that reviews are checked by moderators, the fake review was added almost immediately. Researchers also discovered that Booking.com’s messaging system allowed them to send an external link asking for credit card details to confirm a booking. Which? pointed out that the platform has the capability to block such links but did not do so in this case. The fake listing was eventually removed on August 27, six weeks after it was created. Which? criticized Booking.com for what it called "systemic security failures," noting that fake listings often remain active for long periods before being addressed. In a previous investigation in 2024, it took the company 18 months to request proof of identity for a similar fake listing. According to Booking.com’s policies, hosts are not required to provide photo ID or proof of ownership until three months after a listing goes live. Rory Boland, Editor of Which? Travel, criticized the company's AI systems for failing to detect the fake listing and warned of the risks to consumers. He urged the Prime Minister to call on the UK communications regulator, Ofcom, to enforce the Online Safety Act against platforms that leave users vulnerable to fraud. Booking.com responded by stating that the test was not a true reflection of the platform’s overall experience, explaining that the listing was not visible or "live" for the time period referenced. The company claimed it uses various checks, verification measures, and artificial intelligence to detect and remove fraudulent listings within 24 hours. It also noted that some automatic fraud controls were not triggered because the listing was not open for booking. An Ofcom spokesperson confirmed that platforms are legally required to remove illegal content swiftly once they become aware of it. However, Booking.com is not currently in scope for future rules related to paid-for fraudulent advertising, which would be a matter for the government. Which? reported receiving many complaints from consumers about scam messages and fake listings on the platform and urged Ofcom to investigate Booking.com’s compliance and take strong action to prevent further security breaches.