Summary
- No registry update, RIPE NCC action, or independent, non-registry evidence located for this briefing shows that the Svea abuse-contact surface has changed materially since our previous reports of the split between registered validity and demonstrable accountability.
- The regulatory record cuts the other way: on 17 December 2025, Finansinspektionen refused to take the bank's own remediation claims at face value, issuing Svea Bank AB a remark and a SEK 170 million administrative fine (FI dnr 23-13249) for violations of central anti-money-laundering provisions.
The facts of the financial record are settled enough. On 3 January 2022, Svea Ekonomi AB — previously the parent — was merged into Svea Bank AB, and all of its business continued in the bank; the Finansinspektionen decision of 16 December 2025, announced the following morning, records that transfer in its own background [1][2]. The investigation covered the period 30 April 2022 to 1 May 2023 and found deficiencies in beneficial-owner identification, customer due diligence and the timeliness of measures.
The supervisor concluded the violations were not serious enough to withdraw the licence or issue a warning — but it was serious enough about the bank's own remediation narrative to fine it [1][3].
The registry record has not caught up with any of this. AS211899 'SVEA' remains assigned to ORG-SBA155-RIPE (Svea Bank AB, reg-nr 556158-7634) with abuse-c SEAR1-RIPE [4]. The person object JE4899-RIPE still carries the postal address 'Svea Ekonomi AB', last modified 2022-04-11 — a company that ceased to exist as a legal person in January 2022 [4][5].
Meanwhile the routed prefix 193.105.138.0/24, itself still named SVEA-EKONOMI-SE and described as 'Svea Ekonomi AB', belongs to a third entity, Svea Billing Services AB (ORG-SBSA5-RIPE), and its displayed abuse contact is a third-party mailbox on a Verizon domain, corroborated independently by IPinfo [6][7]. A fourth actor, Svea Hosting AB, operates AS41634, also named 'SVEA', with an abuse mailbox on the svea.net domain and no registry-shown societary link to the bank [8][9]. Svea's own contact page advertises an abuse mailbox without naming the legal entity that operates it [10].
What the RIPE NCC guarantees is only that these references are structurally valid. The abuse-c attribute lives in the organisation object and references a role object containing an abuse-mailbox; changing the address requires editing that role object [11]. Beyond validity, the registry's operator says its role stops: it keeps abuse contacts "valid and up to date", and "there is nothing we can do if a network operator chooses not to reply" to a report [12]. The RIPE Database documentation is consistent on this boundary: a valid abuse-c proves a mailbox exists, not that anyone reads it [13].
Against that backdrop, what this briefing tested was simple: has anything moved since our previous coverage? The answer is no. No updated role object with an operated Svea-domain mailbox, no acknowledged-response evidence, no mirror consistency — none of the observable conditions for durable repair are yet met.
Even the incident signals that exist are indirect: Svea Bank is recruiting a Group ICT Incident Manager [14], and wire reports document data breaches and attempted extortion against Svea Bank and Verisure [15] — evidence that abuse and incident handling matters to this network, and still no evidence that its published abuse channels are answered.
Sources: [1] https://www.fi.se/en/published/sanctions/financial-firms/2025/svea-bank-receives-a-remark-and-administrative-fine/ · [2] https://www.fi.se/contentassets/d388bf1d1d1c47a1ac5dff513567510c/sanktionsbeslut-svea-bank-ab.pdf · [3] https://www.fi.se/sv/publicerat/granskningar/undersokningar/undersokningar-lista/2025/fi-avslutar-undersokning-av-svea-bank/ · [4] http://whois.ipip.net/AS211899 · [5] https://ip.cc/topic/asn/AS211899/ · [6] http://whois.ipip.net/AS211899/193.105.138.0/24 · [7] https://ipinfo.io/193.105.138.185 · [8] http://whois.ipip.net/AS41634 · [9] https://www.cidr-report.org/cgi-bin/as-report?as=AS41634&view=2.0 · [10] https://svea.net/contact · [11] https://www.ripe.net/manage-ips-and-asns/resource-management/abuse-c-information/ · [12] https://www.ripe.net/about-us/support/abuse/ · [13] https://docs.db.ripe.net/Types-of-Queries/Abuse-Contacts/ · [14] https://career.svea.com/jobs/7961466-group-ict-incident-manager-till-svea-bank · [15] https://hk.marketscreener.com/news/indictment-filed-following-data-breaches-and-attempted-extortion-against-svea-bank-and-verisure-ce7f5adcd08ef025 · [16] https://sv.wikipedia.org/wiki/Svea_Bank · [17] https://www.fi.se/sv/publicerat/sanktioner/finansiella-foretag/2022/svea-bank-far-anmarkning-och-sanktionsavgift/ · [18] https://www.svea.com/sv-se/om-oss/fusion · Directory record: https://btw.media/en/directory/svea-eknonomi-abuse-role
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

