Summary

  • Registry timestamps show the recently touched parts of the Svea abuse-contact chain are outside Svea: the SWIP-RIPE role (Tele2 IP Registry, last-modified 2026-07-01) and the organisation object ORG-SBA155-RIPE (a disputed 2026-05-13 timestamp).
  • Svea's own objects are frozen: person object JE4899-RIPE still carries the dissolved Svea Ekonomi AB address, last-modified 2022-04-11; the aut-num dates to 2022-05-13; the PI block 193.105.138.0/24 dates to 2021-02-02 and routes abuse to a third-party Verizon mailbox.
  • The actual abuse mailbox behind the SEAR1-RIPE role handle remains unverifiable from the primary registry, the same retrieval limitation prior coverage reported on 29 September 2026.
  • No independent source shows any Svea mailbox receives or processes abuse reports; absence of evidence is not evidence of the contrary, but it is also not proof of a working channel.

The Svea group's internet presence in the RIPE registry is anchored by AS211899, registered to organisation ORG-SBA155-RIPE — Svea Bank AB, Swedish company registration number 556158-7634 — with sponsoring organisation ORG-TA44-RIPE and maintainer SWIPNET-LIR-MNT. The organisation object sets abuse-c to SEAR1-RIPE, a role object that should hold the single abuse mailbox RIPE policy requires. But read the record as a chain of custody rather than a set of entries, and a dating pattern emerges that no prior coverage had assembled.

Start with what has been touched recently. The SWIP-RIPE role object — the Tele2 IP Registry, rendering abuse[at]tele2.com — shows a last-modified value of 2026-07-01T11:13:26Z. The organisation object ORG-SBA155-RIPE shows 2026-05-13T06:37:38Z on two mirrors, though a third mirror shows 2022-12-01T17:25:15Z, a disagreement that cannot be resolved without primary registry access. Those two objects, one of them disputed, are the only parts of this chain with 2026 dates.

Now the untouched side. The person object JE4899-RIPE — Jorgen Edstrom, listed as admin-c and tech-c of the autonomous system — still lists the address "Svea Ekonomi AB", a legal entity that ceased to exist on 3 January 2022, and shows last-modified 2022-04-11T12:25:22Z. The aut-num itself shows 2022-05-13T06:38:36Z. The PI block 193.105.138.0 - 193.105.138.255, netname SVEA-EKONOMI-SE with description "Svea Ekonomi AB", is registered under ORG-SBSA5-RIPE (Svea Billing Services AB) and has not been modified since 2021-02-02T09:03:55Z.

Its rendered abuse contact is abuse[at]se.verizon.com — a third-party mailbox belonging to a company that is not Svea.

The pattern is the finding. The registry's most recent attention in this chain fell on the sponsoring and maintainer layer, not on the abuse-contact surface itself. Whoever updated SWIP-RIPE in July 2026 and ORG-SBA155-RIPE in May 2026 (if the 2026-05-13 timestamp is correct) was working on registry plumbing — maintaining the LIR relationship — not repairing the record that a reporter would actually use to file an abuse complaint.

What does a reporter see when they query the surface today? It depends on which mirror they read. Sitezilla and IPGeolocation.io render the AS211899 abuse contact as the individual mailbox jorgen.edstrom[at]svea.com, even though the organisation object sets abuse-c: SEAR1-RIPE. RIPE's own abuse-contact documentation explains why: default queries return the related abuse email as a comment line, so the mirror's rendering depends on how it resolves the handle. The IPIP.NET mirror instead shows the organisation object with abuse-c: SEAR1-RIPE intact.

And the handle itself is a dead end. The contents of the SEAR1-RIPE role object were not retrievable in the research for the 29 September 2026 briefing, and they were not retrievable in this run either: the primary RIPE query interface returned no object body through available retrieval, only the generic Webupdates page title. The actual mailbox behind the handle is therefore publicly unproven. Every claim about it rests on mirror renderings with unknown crawl dates — and those mirrors disagree with each other on the organisation object's own last-modified value.

RIPE policy, set out in ripe-705 (proposal 2017-02), requires a mandatory abuse-c in organisation objects, a single abuse-mailbox in a role object, unrestricted whois visibility, and at least annual validation. But the validation the registry performs tests configuration — syntax, domain, mail server — not whether reports are received or processed. RIPE NCC states plainly that processing abuse reports is the network operator's responsibility, and that the registry can do nothing if an operator chooses not to reply. The Svea record is technically valid by that standard.

It is the operation behind the validity that no public source establishes.

There is a regulatory backdrop, and it should be read carefully. On 17 December 2025, Sweden's financial supervisor Finansinspektionen imposed a remark and an administrative fine of SEK 170 million on Svea Bank AB for failures of anti-money-laundering prevention. The decision does not mention the RIPE registry or abuse-contact obligations; it is precedent for accountability standards, not evidence about registry records. But its logic is instructive: the supervisor declined to take the bank's self-reported remediation at face value.

The registry asks its users to apply exactly that standard to abuse contacts — and the timestamp chain here shows nobody has.

What would change the picture? Three dated, observable events: a modification to JE4899-RIPE that replaces the dissolved company's address; a primary-verifiable update to SEAR1-RIPE showing a current, role-owned mailbox; and evidence — independent of the operator — that reports to any Svea mailbox are received and answered. Until then, the dating analysis stands: the chain has been maintained where the maintainer's interests lie, and left frozen exactly where a reporter's remedy begins. Sources: RIPE database query, SEAR1-RIPE; RIPE database query, ORG-SBA155-RIPE; RIPE database query, AS211899; RIPE database query, 193.105.138.0/24; IPIP.NET whois, AS211899; IPIP.NET whois, AS211899 / 193.105.138.0/24; Sitezilla, AS211899; IPGeolocation.io, AS211899; BTW Media briefing, 29 September 2026: the Svea abuse-contact role; BTW Media sanction spotlight, 17 December 2025 Finansinspektionen decision; RIPE database dump index, ftp.ripe.net; RIPE Database documentation: abuse contacts; RIPE policy document ripe-705.