Summary

  • No registry update, RIPE NCC action, or independent, non-registry evidence located for this briefing shows that the Svea abuse-contact surface has changed materially since our previous reports of the split between registered validity and demonstrable accountability.
  • The regulatory record cuts the other way: on 17 December 2025, Finansinspektionen refused to take the bank's own remediation claims at face value, issuing Svea Bank AB a remark and a SEK 170 million administrative fine (FI dnr 23-13249) for violations of central anti-money-laundering provisions.

The facts of the financial record are settled enough. On 3 January 2022, Svea Ekonomi AB — previously the parent — was merged into Svea Bank AB, and all of its business continued in the bank; the Finansinspektionen decision of 16 December 2025, announced the following morning, records that transfer in its own background [1][2]. The investigation covered the period 30 April 2022 to 1 May 2023 and found deficiencies in beneficial-owner identification, customer due diligence and the timeliness of measures.

The supervisor concluded the violations were not serious enough to withdraw the licence or issue a warning — but it was serious enough about the bank's own remediation narrative to fine it [1][3].

The registry record has not caught up with any of this. AS211899 'SVEA' remains assigned to ORG-SBA155-RIPE (Svea Bank AB, reg-nr 556158-7634) with abuse-c SEAR1-RIPE [4]. The person object JE4899-RIPE still carries the postal address 'Svea Ekonomi AB', last modified 2022-04-11 — a company that ceased to exist as a legal person in January 2022 [4][5].

Meanwhile the routed prefix 193.105.138.0/24, itself still named SVEA-EKONOMI-SE and described as 'Svea Ekonomi AB', belongs to a third entity, Svea Billing Services AB (ORG-SBSA5-RIPE), and its displayed abuse contact is a third-party mailbox on a Verizon domain, corroborated independently by IPinfo [6][7]. A fourth actor, Svea Hosting AB, operates AS41634, also named 'SVEA', with an abuse mailbox on the svea.net domain and no registry-shown societary link to the bank [8][9]. Svea's own contact page advertises an abuse mailbox without naming the legal entity that operates it [10].

What the RIPE NCC guarantees is only that these references are structurally valid. The abuse-c attribute lives in the organisation object and references a role object containing an abuse-mailbox; changing the address requires editing that role object [11]. Beyond validity, the registry's operator says its role stops: it keeps abuse contacts "valid and up to date", and "there is nothing we can do if a network operator chooses not to reply" to a report [12]. The RIPE Database documentation is consistent on this boundary: a valid abuse-c proves a mailbox exists, not that anyone reads it [13].

Against that backdrop, what this briefing tested was simple: has anything moved since our previous coverage? The answer is no. No updated role object with an operated Svea-domain mailbox, no acknowledged-response evidence, no mirror consistency — none of the observable conditions for durable repair are yet met.

Even the incident signals that exist are indirect: Svea Bank is recruiting a Group ICT Incident Manager [14], and wire reports document data breaches and attempted extortion against Svea Bank and Verisure [15] — evidence that abuse and incident handling matters to this network, and still no evidence that its published abuse channels are answered.

Sources: [1] https://www.fi.se/en/published/sanctions/financial-firms/2025/svea-bank-receives-a-remark-and-administrative-fine/ · [2] https://www.fi.se/contentassets/d388bf1d1d1c47a1ac5dff513567510c/sanktionsbeslut-svea-bank-ab.pdf · [3] https://www.fi.se/sv/publicerat/granskningar/undersokningar/undersokningar-lista/2025/fi-avslutar-undersokning-av-svea-bank/ · [4] http://whois.ipip.net/AS211899 · [5] https://ip.cc/topic/asn/AS211899/ · [6] http://whois.ipip.net/AS211899/193.105.138.0/24 · [7] https://ipinfo.io/193.105.138.185 · [8] http://whois.ipip.net/AS41634 · [9] https://www.cidr-report.org/cgi-bin/as-report?as=AS41634&view=2.0 · [10] https://svea.net/contact · [11] https://www.ripe.net/manage-ips-and-asns/resource-management/abuse-c-information/ · [12] https://www.ripe.net/about-us/support/abuse/ · [13] https://docs.db.ripe.net/Types-of-Queries/Abuse-Contacts/ · [14] https://career.svea.com/jobs/7961466-group-ict-incident-manager-till-svea-bank · [15] https://hk.marketscreener.com/news/indictment-filed-following-data-breaches-and-attempted-extortion-against-svea-bank-and-verisure-ce7f5adcd08ef025 · [16] https://sv.wikipedia.org/wiki/Svea_Bank · [17] https://www.fi.se/sv/publicerat/sanktioner/finansiella-foretag/2022/svea-bank-far-anmarkning-och-sanktionsavgift/ · [18] https://www.svea.com/sv-se/om-oss/fusion · Directory record: https://btw.media/en/directory/svea-eknonomi-abuse-role