Consumer watchdog Which? listed 10 Downing Street on Booking.com on 18 June as a "1 bedroom apartment in the heart of London," complete with the exact address and a photograph of the prime minister's residence. The listing promised a four-minute walk to the Houses of Parliament. It stayed live until 27 August — six weeks — before Booking.com removed it. The test was methodical. Researchers set the listing so users had to request a stay rather than book automatically, opened the booking window briefly, and had a Which? researcher complete a transaction. Booking.com processed payment for a week-long stay. More than six weeks later, that money had still not been refunded. A fake review describing the stay as "exceptional" and mentioning "hanging out with Larry the cat" — a reference to Downing Street's resident feline — was uploaded to the platform. Booking.com sent a message saying the review would be checked by moderators. It was published almost immediately. The researchers also used Booking.com's own messaging system to send an external URL requesting credit card details, a classic phishing vector. The platform told Which? it had the ability to block such URLs but did not. Booking.com's defense was narrow and telling. A spokesperson said the property "was not visible to customers or 'live' for the time period referenced" and that because it was not open and bookable, "some of its automatic fraud controls were not triggered." Translation: the platform's fraud systems are designed to catch fraud only after it is already operational, not at the point of listing creation. The company claimed it uses "a range of checks, verification measures and artificial intelligence" to detect and remove fraudulent listings within 24 hours. Rory Boland, editor of Which? Travel, drove the point home: "If Booking.com's so-called sophisticated AI systems can't spot that 10 Downing Street is not a holiday rental, then it's no wonder scammers can exploit the platform so easily." Which? said its investigation uncovered "systemic security failures across the platform" and urged Ofcom to investigate. Ofcom's response revealed the regulatory gap. The communications regulator said platforms have legal duties to take down illegal user-generated content once known, but added that "Booking.com is not in scope of future rules that will apply to paid-for fraudulent advertising, and any change to that would be a matter for government." The platform sits in a regulatory blind spot: it hosts paid-for listings that function like advertising but are classified as user-generated content. The structural problem is not that someone listed Downing Street as a joke. It is that a platform processing billions in travel bookings has no meaningful verification at the point of listing creation, no functional review moderation, no URL-blocking on its own messaging system, and a refund process that takes more than six weeks for an obviously fraudulent transaction. Every one of these failures is a vector that real scammers exploit against real consumers every day.