The consumer advocacy group Which? has accused Booking.com of failing to implement adequate security measures after researchers successfully created a fraudulent listing for 10 Downing Street. The property, described as a one-bedroom apartment in a "prime city centre location," remained on the platform for two months before being removed on August 27.
During a 20-minute window when the listing was active, 14 users attempted to book the residence. Which? researchers were also able to post a satirical review claiming they had "hung out" with Larry the cat, the resident mouser at the Prime Minister’s home. Furthermore, the group noted that the platform failed to flag a message containing an external link for payment details, a common tactic used in phishing scams.
Rory Boland, editor of Which? Travel, argued that the incident proves the platform's artificial intelligence and verification systems are "unfit for purpose." He warned that such vulnerabilities leave travelers susceptible to significant financial loss.
In response, a Booking.com spokesperson stated that the listing was not "live" for the duration of the two months, which prevented some automated fraud controls from triggering a full removal. The company maintained that it employs a range of verification measures and that the majority of fraudulent listings are removed within 24 hours. Regarding the external link, the firm noted it provides "visible reminders" to users to avoid clicking suspicious links.
Which? is now calling for stricter enforcement of the Online Safety Act (OSA), suggesting that regulators like Ofcom should take a more aggressive stance against platforms that fail to swiftly address fraudulent content. An Ofcom spokesperson noted that platforms already have legal obligations to remove illegal user-generated content once they are made aware of it.
Source: BBC News
暂无评论。快来发表第一条评论吧。