Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Tuesday 11 March 2025 7:00 am  |  Updated:  Wednesday 12 March 2025 1:44 pm

Booking.com prone to scammers due to weak security, warns watchdog

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
Booking.com open to scammers due to weak security, warns watchdog
Booking.com open to scammers due to weak security, warns watchdog (Photo by Noam Galai/Getty Images for Booking.com)

A lack of effective security measures is leaving Booking.com vulnerable to scammers, consumer champion Which? has warned.

Which? said the platform suffers from an easily hacked messaging system, failure to remove scam listings, and a lack of identity checks on property owners.

The watchdog’s findings, which come as the Online Safety Act‘s illegal codes are set to take effect later this month, found that Booking.com’s lax security policies make it easy for fraudsters to exploit travellers.

Booking.com was the most visited travel and tourism website globally in January 2025, according to Statista.

Flawed security methods

As part of its investigation, Which? was able to list a fake holiday home on the website in under 15 minutes.

Unlike rival platforms like AirBnb, Booking.com does not require any identity verification before allowing the listing to go live.

This lack of security checks has flooded the platform with fraudulent listings.

When Which? searched Booking.com reviews for the word ‘scam’ in the summer of 2024, and it found hundreds of complaints from customers who had paid for accommodation that did not exist.

The consumer watchdog reported 52 suspicious listings to Booking.com, which removed most of them.

Yet, the company dismissed many complaints, claiming that the properties were not scams but owners who had forgotten to update their availability accurately when closed or temporarily shut down.

Yet, when Which? checked again in November, it found the same recurring problem: 36 properties still had hundreds of negative reviews claiming they were scams.

The watchdog revealed numerous customer horror stories.

One man, after arriving at an address which “looked like a dentist’s surgery” rather than a holiday home, was later joined by two other angry couples victim to the same fraudulent listing.

The holiday booking platform then refused to refund him until Which? intervened two months later.

Booking.com insisted the customer had not been scammed, claiming instead that it was the owner’s responsibility to issue a refund.

Security loopholes and two factor authentication

The investigation also revealed that the website’s security systems were insufficient to prevent scammers from listing fake properties or hacking real ones.

The platform said it restricts new hosts from accepting prepayments until they receive bookings and reviews, but scammers seem to have found ways around this rule.

Read more

Fraud losses surge as scammers use AI to manipulate victims

Executives argue the measures threaten firms’ business models, particularly smaller fintechs more relatively exposed to fraud and with less capital to cover mandatory reimbursement. (Photo by Artur Widak/NurPhoto via Getty Images)

For example, a Glasgow property listing received 36 one-star reviews, nearly all of which described it as a scam and warned that the website had not issued refunds.

The platform only removed the listing following a request from Which?.

More recently, Booking.com introduced two factor authentication (2FA) for hosts and guests to prevent unauthorised account access.

However, a cyber security specialist contacted the watchdog with evidence that 2FA on Booking.com had serious flaws: his 2FA was not working properly on his guest account. This means that if a hacker accessed his email, they could easily log in and read all of his messages without additional verification.

Which? said that Booking.com has not yet fixed this issue.

Another serious concern was the use of external payment links, which fraudsters can send through Booking.com’s own messaging system.

Several Which? interviewees reported receiving messages containing links that redirected them away from the platform, a common tactic scammers used to bypass security protections.

Booking.com under scrutiny

On March 17, the Online Safety Act’s illegal harms codes will come into force, requiring platforms like Booking.com to do more to prevent fraud.

Under the Act, user-generated fraud will be explicitly covered.

This means fraudulent property listings on travel sites will fall under regulatory scrutiny.

Which? has outlined basic security changes that Booking.com must make to protect its users from fraud, like mandatory identity checks and enforced 2FA.

The watchdog is also urging Ofcom, the regulator behind the Act, to take decisive action.

Director of policy and advocacy, Rocio Concha, warned: “It’s really worrying that so many scams are slipping through the net.”

“Ofcom should take note of these findings as the codes come into force. If these issues persist, Ofcom must make use of its new powers and not hesitate to take action against Bookin.com and other platforms failing to prevent fraudsters from scamming their customers”, he added.

A booking.com spokesperson said: “Online fraud is unfortunately a battle many industries are facing, however thanks to the robust security measures we have in place and our continuous efforts to enhance them, we are able to detect and block the vast majority of fraudulent activity.”

“In the rare instance that a scammer finds a way to temporarily circumvent our controls, we seek to shut down the activity as quickly as possible and support any impacted customers quickly. In addition, we always recommend that customers read through our reviews and property rating scores before booking, to ensure they can see the views of others who have also stayed at the property.”

Read more

HSBC coughs up $25m over Australian scam failures

HSBC's Canary Wharf office.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

People & Organisations

  • Booking.com
  • ofcom
  • Online Safety Act
  • scams
  • Which?

Trending Articles

  • Revealed: Secret Treasury plan to tax State Pension before it is paid out

  • Two solicitors linked to Post Office scandal charged with misconduct

  • Burnham’s new chief of staff ran City firm advising Thames Water and rival Heathrow bidder

  • Barclays and Lloyds join banking sector plan for digital ID

  • Reeves’ new tax charge on cash ISAs faces fierce industry backlash

More from City PM

  • Fraud losses surge as scammers use AI to manipulate victims

    Personal Finance
    Executives argue the measures threaten firms’ business models, particularly smaller fintechs more relatively exposed to fraud and with less capital to cover mandatory reimbursement. (Photo by Artur Widak/NurPhoto via Getty Images)
  • HSBC coughs up $25m over Australian scam failures

    Banking
    HSBC's Canary Wharf office.
  • Starmer clings on as defence spending plan in disarray after resignations

    Politics
    Breaking news concept with digital world map and glowing data streams, symbolizing global communication and technology tre...
  • ‘Act now’: AI models capable of attacks on governments months away, Five Eyes warn

    Tech
    GettyImages 158774123 showcases a relevant business meeting scene, highlighting diverse professionals engaged in discussion.
  • Barclays and Lloyds join banking sector plan for digital ID

    Banking
    Banking app interface showing financial transactions and account balance on a smartphone screen, emphasizing digital finan...
  • Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

    Business Wire
  • WP Engine Enhances Global Edge Security With Bot Management to Control AI-Driven Website Traffic

    Business Wire
  • FEINDEF 27 Accelerates Commercialisation, Surpassing FEINDEF 25’s Total Exhibition Area by 25% With One Year to Go

    Business Wire

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM. All rights reserved.
About · Contact · Terms · Privacy