Booking.com has been accused of failing to tackle fake listings after customers were sent to an address that turned out to be a Wetherspoons pub.
Which? said staff at the pub had been turning away up to 20 tourists a day after scammers used the address of The Liberty Bounds, near Tower Bridge, for a listing advertising a “block of luxury apartments”.
Fake listing for 10 Downing Street
The consumer watchdog said it was also able to set up a fake listing for 10 Downing Street on Booking.com earlier this month, after being alerted to several reports from consumers about similar fraudulent listings created by real scammers.
In August, Paul Dawson, 55, from Loughborough, booked a one-night stay for himself, his wife and daughter through Booking.com at The London Crown apartments while visiting London to watch a musical in the West End. He paid £73.
But two days after making the booking, he received an email from The London Crown containing a link to a fake Booking.com page, which asked him to provide his bank details.
Customer told to visit non-existent property
Mr Dawson told Which? that he contacted Booking.com because he suspected something was wrong. However, he said the platform told him he would need to visit the fake apartment and wait until after 7pm before it would relocate him.
This was despite Mr Dawson explaining to them that he had since discovered the address shown in the listing was actually The Liberty Bounds pub.
He told Which?: “I explained to the support staff that I had autistic children and the idea of turning up at a clearly non-existent property at 10.30pm would have been catastrophic.
“This did not change their response that I needed to go to the property. They said that if it was not possible to check in then I could contact them again and they would find an alternative.”
The listing for the London Crown apartments was still visible on Booking.com on September 23, with over 250 negative reviews from August and September along with a handful of – likely fake – positive reviews, Which? said.
Reviews reported scam but were ignored
Many of the reviews from customers said they told Booking.com that it was a scam but had been ignored.
One customer said: “I reported it to Booking.com three days before check-in but they refused to do anything.”
Another customer, from Spain, complained that she and her friend had been left stranded, writing: “Two girls alone in London at two o’clock in the morning with no accommodation.”
Booking.com also has an AI trip planner called Dot, which allows users to ask questions. On The London Crown listing page a Which? researcher asked: “Is this a real property, or is it a scam?”.
It replied: “The London Crown is a legitimate property located in the centre of London. It offers various amenities such as free WiFi, free bikes, and free private parking. It is conveniently located near Longleat Safari Park and Longleat House, with London City Airport just 10 km away. Based on the detailed description and amenities listed, the London Crown appears to be a real and well-equipped property.”
Dot failed to recognise that Longleat Safari Park was more than hundred miles from London.
Which? said it was also made aware of a property listed as “Apartments near Big Ben”, with the address given as Portcullis House, which is part of the House of Commons estate, where hundreds of MPs work.
Booking.com response
Booking.com told Which? that in both cases, listings for legitimate properties had been targeted by a sophisticated phishing attack, allowing criminals to hijack the listings.
Which? Travel editor Rory Boland said: “Not only does Booking.com refuse to take scams seriously, but its requirement that guests turn up to properties, even when it has been advised the property doesn’t exist, is utterly reckless. It’s frightening, humiliating and risks people’s safety.
“Instead of taking action when fraudulent listings are reported, Booking.com prefers to let its customers bear the financial and safety risks.
“Ofcom must show it will use its powers to get tough with irresponsible online platforms that leave consumers wide open to fraud.”
Booking.com said: “Our investigation indicates that both properties – which are legitimate and have hosted guests – were targeted by a sophisticated phishing attack. The attack affected the properties’ own computer systems and gave cybercriminals temporary, unauthorised access to the accommodation’s Booking.com account.
“We take incidents like this extremely seriously, and suspended bookings at both properties, as well as supporting affected customers.”
An Ofcom spokesman said: “Fraud online can have serious consequences for victims and platforms have clear legal duties to take down illegal content generated by users once they become aware of it.
“More broadly, we’ve shown that we’ll use our enforcement powers against platforms that fail to comply with the Online Safety Act, and have already launched investigations into over 100 sites.”