Scammers Hijack Listings, Sending Travelers to London Pub Instead of Hotels
Fraudulent bookings on Booking.com have led tourists to a Wetherspoon pub, with platforms urged to adopt more robust prevention measures.
A sophisticated phishing attack has led to fraudulent hotel listings on Booking.com, directing travelers to a Wetherspoon pub in London instead of the luxury apartments they booked. Paul Dawson, who paid £73 for a one-night stay for his family to see the musical Hamilton, discovered the address listed for The London Crown apartments was actually The Liberty Bounds pub near Tower Bridge.
Consumer protection organization Which? reported that Wetherspoon staff have been turning away as many as 20 tourists daily who were misled by these scams. The fraudsters used the pub's address for listings advertising "luxury apartments." Similar scams were reported for a property listed as "Apartments near Big Ben," with the address given as Portcullis House, part of the House of Commons estate.
Booking.com stated that legitimate property listings were targeted by a "sophisticated phishing attack," enabling criminals to gain unauthorized access to the accommodation accounts. The company suspended bookings for both affected properties and is assisting customers who were defrauded. Wetherspoon informed Booking.com of the scam as soon as it was discovered and has repeatedly requested the permanent removal of the fraudulent listing.
Reviews for The London Crown listing, posted in August and September, included hundreds of negative comments alongside a small number of potentially fake positive reviews. Although the listing was temporarily removed, it reappeared, with booking capabilities later blocked. The BBC noted on Thursday that the page displayed a message stating the property was not taking reservations.
Wetherspoon criticized the situation as "unacceptable" and urged Booking.com to implement stronger procedures to prevent such fraudulent listings from appearing. Many customers reported that their warnings about the scam to Booking.com were ignored, with some left stranded in London with no accommodation.
Booking.com's AI trip planner, Dot, also failed to identify the scam when asked about The London Crown. The AI incorrectly stated the property was legitimate and even cited Longleat Safari Park, located over 100 miles away in Wiltshire, as a nearby attraction.
A spokesperson for Booking.com said the company takes such incidents "extremely seriously." The phishing attack compromised the properties' computer systems, granting cybercriminals temporary, unauthorized access to their Booking.com accounts.
Ofcom, the UK's communications regulator, emphasized that online fraud has severe consequences and that platforms have legal obligations to remove illegal user-generated content once they are aware of it. The regulator has launched investigations into over 100 sites for non-compliance with the Online Safety Act.