Summary

  • On 17 December 2025, Finansinspektionen (FI) issued Svea Bank AB a remark and a SEK 170,000,000 administrative fine for violations of key anti-money-laundering provisions; the decision concerns AML compliance, not abuse-contact handling.
  • The RIPE registry surface for the Svea family remains split: AS211899 is registered to Svea Bank AB (ORG-SBA155-RIPE, abuse-c SEAR1-RIPE) with an abuse contact that is a personal svea.com mailbox rather than a role account, while person object JE4899-RIPE still lists the address of the dissolved Svea Ekonomi AB, and the legacy netblock 193.105.138.0/24 points to a Verizon-associated third-party mailbox.
  • A fresh review of the located record found no independent, non-registry evidence that the Svea abuse roles have received and acted on abuse reports since the merger.
  • The FI decision itself supplies the accountability standard: the regulator explicitly declined to accept Svea's remediation claims at face value, judging its cooperation "not more active than could be expected."
  • No equivalent external verification mechanism exists for abuse-contact handling; RIPE NCC's own rules require only that a contact exists and is up to date, not that anyone answers.

The sanction that set the standard

Finansinspektionen, Sweden's financial supervisory authority, notified Svea Bank AB at 08:00 on 17 December 2025 that it would receive a remark and a sanction of SEK 170,000,000, under decision dnr 23-13249 (FI press release; decision document). The formal decision opens with two operative points: "Finansinspektionen ger Svea Bank AB (556158–7634) en anmärkning" — a remark — and "Svea Bank AB ska betala en sanktionsavgift på 170 000 000 kronor" — a fine of SEK 170 million. The violations concerned key anti-money-laundering provisions, not network abuse handling.

The investigation's scope matters for anything that follows. FI's own summary states that it covered the bank's general risk assessment, customer risk assessment and customer due diligence measures, for the period 30 April 2022 to 1 May 2023, limited to legal-person customers (FI investigation summary). Deficiencies were found in the general risk assessments and in customer due diligence. Nothing in that mandate touches the abuse mailbox attached to an autonomous system in a regional internet registry.

Where responsibility legally lives, and what the record still shows

The same decision document records the corporate transition that anchors this entire case: "Den 3 januari 2022 fusionerades Svea Ekonomi AB, som var Sveas moderbolag, med Svea. All verksamhet som drevs av Svea Ekonomi AB kom därefter att drivas av Svea" — Svea Ekonomi AB, the group's parent, merged into Svea, and all activity it carried on was thereafter carried on by Svea. Legally, the survivor bank holds every obligation the dissolved parent left behind.

Yet the registry surface has not followed the legal fact. Public RIPE mirrors show AS211899 registered to Svea Bank AB through organisation object ORG-SBA155-RIPE, whose abuse-c is SEAR1-RIPE, with the displayed abuse contact for the AS being a personal svea.com mailbox for the named contact person (IPGeolocation mirror; IPIP.NET mirror). The person object anchoring the technical contact, JE4899-RIPE for Jorgen Edstrom, still lists the address "Svea Ekonomi AB" — a company that has not existed since 3 January 2022. One mirror shows the organisation object last-modified 2026-05-13T06:37:38Z, while another shows differing dates for the same object, so even the freshness of the record is contested between mirrors.

The heterogeneity runs deeper. The legacy netblock 193.105.138.0/24, registered under Svea Billing Services AB (ORG-SBSA5-RIPE, abuse-c AR23510-RIPE), displays a Verizon-associated third-party mailbox as its abuse contact (IPIP.NET netblock record). IPinfo independently shows the same Verizon-associated mailbox for 193.105.138.185 under AS211899 (IPinfo record). A third mailbox belongs to the sponsoring organisation Tele2 IP Registry (ORG-TA44-RIPE) shown on the AS record. So a report about abuse within the Svea footprint could be routed, depending on which object the reporter resolves, to a personal svea.com address, a third-party telecom mailbox, or a Verizon-associated legacy address. Prior BTW reporting documented this split; this report re-verified it against the current mirrors and found it unchanged.

The structural boundary: what the registry guarantees

RIPE NCC's own support documentation draws the line plainly: "Our role is to ensure that all abuse contacts are valid and up-to-date in the RIPE Database. From there, it is the responsibility of the network operator to handle your abuse report. There is nothing we can do if a network operator chooses not to reply" (RIPE NCC abuse support page). The policy basis is equally explicit: following a June 2011 community proposal, the RIPE policy "Abuse Contact Management in the RIPE Database" made a dedicated abuse contact via the organisation object mandatory for every inetnum, inet6num and aut-num (ripe-658).

Two consequences follow. First, the presence of an abuse-c is a compliance artifact: it proves the field exists and points somewhere, nothing more. Second, RIPE NCC itself disclaims the reliability of the data it surfaces — the RIPEstat Abuse Contact Finder documentation notes that abuse contact information is "in many cases incorrect or not available" (RIPEstat documentation). A registry record is an evidentiary lead, never a proof of staffing, monitoring or response.

The durability question, tested against the record

Prior BTW coverage, published on 29 September 2026, reviewed thirteen primary and secondary sources and found no independent, registry-external evidence that SEAR1-RIPE, AR23510-RIPE or the jorgen.edstrom mailbox receive and act on abuse reports after the merger (prior BTW briefing). The sources located in this run — regulator documents, the company's own statement, third-party mirrors, RIPE's policy corpus — add nothing that changes that finding. No responsiveness test of any Svea mailbox was performed here, and absence of evidence of handling is not evidence of absence; but the burden of proof sits with the party claiming the repair, not the observer noting its absence.

What makes this more than a registry-hygiene story is the standard FI applied to the one domain it could verify. The decision document records that Svea claimed extensive remediation — a programme plan, additional AML staffing — and that FI considered these claims but judged the cooperation "not more active than could be expected" and did not treat remediation as a ground to refrain from intervening (FI decision document). Svea's own public statement the same day, quoting CEO Lennart Ågren, asserted heavy investment in organisational, procedural and system enhancements for AML and counter-terrorist financing work, and said the bank would analyse the decision and take any remaining measures (Svea statement via TT). That is a self-report about AML; it says nothing about abuse-contact operation, and it is precisely the kind of claim a regulator refused to credit without evidence.

The asymmetry is the finding. In the AML domain, Svea's remediation claims met a supervisor empowered to investigate, quantify deficiencies and discount self-reported progress. In the abuse-contact domain, no equivalent mechanism exists: RIPE NCC validates that the field is present and current, and its own documentation acknowledges it can do nothing if an operator chooses not to reply. The same corporate family therefore faces two very different accountability regimes for two categories of external report — one backed by coercive audit, one backed by a mandatory field and good faith.

What durable repair would actually look like

For the repair to be proven rather than asserted, the evidence would need to be independent of the party claiming it and independent of the registry itself. Four observable categories would qualify:

  1. Registry convergence under a verifiable timestamp. The person object JE4899-RIPE no longer naming a dissolved company, the abuse-c surface consolidated to a dedicated, monitored role account, and mirror-visible last-modified dates agreeing across mirrors. This is the cheapest signal and proves only housekeeping — but its absence after nearly four years and a regulatory sanction is itself informative.
  2. Independent inbound corroboration. A named third party — an abuse handler, a blocklist maintainer, a receiving network — documenting on the record that a report sent to a Svea abuse role was acknowledged and actioned, with dates. Nothing of this kind appears in the located record.
  3. Regulatory or contractual evidence. Any supervisory or contractual instrument addressing abuse-contact handling as part of remediation. The FI decision covers AML only; applying its evidentiary standard to abuse contacts is an analytical frame adopted here, not a regulatory finding.
  4. A verified responsiveness test. A controlled, documented report sent to the registered contacts with a timestamped outcome. This report deliberately did not perform one; it notes only that none is documented anywhere in the public record located.

Until at least one of these exists, the honest description of the Svea abuse surface remains the one prior coverage reached: formally valid, operationally unproven. The FI sanction did not change that description — and, read closely, it teaches exactly why it should not be accepted on assertion.