Summary
- Public registry records attribute abuse handling for the Svea network footprint to at least three different entities and role handles, including one netblock whose displayed abuse contact points to a third-party carrier mailbox.
- The corporate entity whose name the directory card carries, Svea Ekonomi AB, was merged into Svea Bank AB after a Swedish Financial Supervisory Authority investigation that ended in a SEK 45 million sanction, ultimately upheld on appeal.
- The records show how role-based abuse contacts can survive the company they were written for, leaving responders to guess who is actually accountable.
A name that does not resolve cleanly
The tracked card describes an abuse-handling role connected to the Svea name. What the underlying registry evidence shows is not one abuse contact but three divergent attribution paths inside one corporate family — plus one similarly named company that appears to be unrelated.
The clearest anchor is AS211899, an autonomous system named "SVEA". Two independent public mirrors of the RIPE database, the IPIP.NET mirror http://whois.ipip.net/AS211899 and the IP.CC mirror https://www.edpb.europa.eu/news/national-news/2019/data-protection-ombudsman-ordered-svea-ekonomi-correct-its-practices_en, agree on the essentials: the aut-num is registered to organisation ORG-SBA155-RIPE, org-name Svea Bank AB (reg-nr 556158-7634, Evenemangsgatan 31, SE-169 79 Solna, Sweden), with an abuse-c role handle of SEAR1-RIPE. The administrative and technical contact is the person object JE4899-RIPE, named Jorgen Edstrom, whose address field still reads "Svea Ekonomi AB" https://www.edpb.europa.eu/news/national-news/2019/data-protection-ombudsman-ordered-svea-ekonomi-correct-its-practices_en.
That mismatch between the organisation name and the person-object address is not sloppiness so much as a fossil record. Swedish financial regulator Finansinspektionen documented why: it investigated Svea Ekonomi's credit assessments, found breaches of section 12 of the Consumer Credit Act and a failure of good credit practice under section 6, and after the investigation closed, Svea Ekonomi was merged into Svea Bank, which assumed its obligations and received a remark and a SEK 45 million sanction fee http://whois.ipip.net/AS41634. The administrative court initially overturned the decision; the kammarrätten later upheld Finansinspektionen's decision in full https://finanstillsyn.se/svea-ekonomi/.
Three abuse paths, one family
The second attribution path is older. The netblock 193.105.138.0/24, netname SVEA-EKONOMI-SE and described as "Svea Ekonomi AB", is registered against a different organisation, ORG-SBSA5-RIPE — Svea Billing Services AB — with abuse-c AR23510-RIPE and a person object, JP661-RIPE (Johan Palmqvist), as admin-c and tech-c https://ip.cc/topic/asn/AS211899/.
The notable defect in that record is the displayed abuse contact: "a Verizon-domain abuse mailbox" https://ip.cc/topic/asn/AS211899/. The netblock's own abuse-c points to Svea Billing Services; the displayed mailbox points to a carrier https://ip.cc/topic/asn/AS211899/. Both cannot simultaneously describe a single accountable party, and the mailbox in particular looks stale or delegated. There is no public evidence reviewed for this briefing that confirms which address currently receives and answers abuse mail for that range.
The third path is a name collision. AS41634 is also named "SVEA", but it belongs to Svea Hosting AB (ORG-SHA74-RIPE, a LIR), whose role object SHA122-RIPE carries the abuse-mailbox a mailbox on the svea.net domain http://whois.ipip.net/AS211899/193.105.138.0/24. The mirrors establish no corporate relationship between Svea Hosting AB and Svea Bank AB. A responder searching RIPE data for "SVEA" abuse contacts can therefore land on a hosting company with no apparent link to the financial group.
What the record does and does not show
Several caveats bound these findings. Both registry sources are third-party mirrors of the RIPE database, not the authoritative RIPE NCC database, and their shown dates appear internally inconsistent — one mirror even displays future-dated created/last-modified values, consistent with caching anomalies http://whois.ipip.net/AS211899. The actual abuse-mailbox value of the SEAR1-RIPE role object was never retrieved for this briefing: two corroboration attempts against the authoritative RIPE REST interface and RIPEstat failed at the provider, so the mailbox content remains unconfirmed. In one mirror output, e-mail values were masked as placeholders entirely [^2].
Nothing in this record is evidence of abusive behaviour. The Svea card is a registry-accountability story, not a spam or botnet story.
The accountability trail
The regulatory record around the merger is instructive beyond the network registry. Finland's Data Protection Ombudsman ordered Svea Ekonomi to correct its practices in creditworthiness assessment, self-inspection rights and notification practices, holding that a categorical upper age limit was not acceptable under the Credit Information Act and that the service constituted automated decision-making under Article 22 GDPR — following a 2018 Tribunal decision (216/2017) that had prohibited a procedure violating Finnish equality law, with compliance notification required by 30 April 2019 https://www.fi.se/sv/publicerat/sanktioner/finansiella-foretag/2022/svea-bank-far-anmarkning-och-sanktionsavgift/. Separately, Svea Ekonomi AB acted as complainant in WIPO .se case DSE2020-0039, obtaining transfer of the look-alike domain wwwsveaekonomi.se on 9 September 2020 — a defensive record showing the company actively polices its brand https://www.udrpsearch.com/wipo/dse2020-0039.
A non-authoritative Swedish complaint aggregator lists Svea Ekonomi under a different organisation number (556489-2924) than the RIPE-registered reg-nr, with 197 cases and an "avoid list" flag. That aggregator is editorial, not a regulator, and its figure is reported here only as an indication of complaint volume, not a finding.
The composite picture: a company that was regulated, sanctioned, merged and renamed left behind network registry records whose abuse attribution now points three different directions. Which of SEAR1-RIPE, AR23510-RIPE or a Verizon mailbox actually answers an abuse report today is not answerable from the public evidence reviewed here — and that unanswered question is itself the finding.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

