Summary

  • RIPE NCC validates only that an abuse mailbox is technically reachable; it explicitly states it has no mandate over how a network operator handles reports (RIPE Labs).
  • Registry records for AS211899 show Svea Bank AB as the post-merger organisation, while the linked person object JE4899-RIPE still carries the address of the dissolved Svea Ekonomi AB (mirror).
  • The legacy block 193.105.138.0/24 still names Svea Ekonomi AB and displays a third-party Verizon mailbox as its abuse contact (mirror; IPinfo).
  • No independent, non-registry evidence shows the registered Svea abuse roles receive and act on reports; on the public record they function as administrative artifacts.

Three earlier BTW articles documented the Svea registry drift itself: the three differently named contact paths, the third-party Verizon mailbox, and the RIPE remedy instruments. This briefing asks the question those pieces left open: is there any evidence that these contact points are actually operated?

The corporate record fixes the baseline. Svea Ekonomi AB, registration number 556489-2924, merged with its subsidiary Svea Bank AB (556158-7634) on 3 January 2022, with all agreements and obligations transferring automatically (merger letter; Svea merger page). After that date, Svea Ekonomi AB ceased to exist as a legal person.

The registry's response was partial. The organisation object ORG-SBA155-RIPE for AS211899 was created on 12 May 2022, after the merger, under the new name Svea Bank AB, with abuse-c SEAR1-RIPE and a mailbox registered to an individual. But the person object JE4899-RIPE — Jorgen Edstrom — still lists the address "Svea Ekonomi AB" in 2026. On the legacy netblock SVEA-EKONOMI-SE (193.105.138.0/24), the description still reads Svea Ekonomi AB under parent organisation Svea Billing Services AB (ORG-SBSA5-RIPE, abuse-c AR23510-RIPE), and the displayed abuse contact is a third-party mailbox (a Verizon address).

What the registry guarantees is deliberately narrow. The RIPE NCC states: "Our role is to ensure that all abuse contacts are valid and up-to-date in the RIPE Database. From there, it is the responsibility of the network operator to handle your abuse report. There is nothing we can do if a network operator chooses not to reply" (RIPE NCC abuse-c information). The ripe-705 validation regime checks syntax, domain and mail-server configuration, and explicitly excludes "scenarios where the 'abuse-mailbox:' attribute is correctly configured but reports are not followed up in a way that the reporter would like" (RIPE Labs). RIPE Labs guidance adds that if a contact does not respond, reporters may try admin-c or tech-c objects or escalate to law enforcement (RIPE Labs).

The regulator's record does not fill the gap. Finansinspektionen's decision of 17 December 2025 imposed a reprimand and a SEK 170,000,000 sanction on Svea Bank AB for anti-money-laundering breaches covering 30 April 2022 to 1 May 2023 (decision; investigation summary). That is a real accountability outcome — on a different track. It says nothing about whether Svea's network abuse contacts are staffed or responsive.

The conclusion follows from the evidence's shape. Registry validity is a floor; operational responsiveness is the test. Across thirteen sources, none shows a timestamped report, an attributable reply, or observable remediation through the Svea abuse roles after the merger. Pending such proof, the honest classification is administrative artifact: objects that exist, validate, and route mail somewhere — with no public demonstration that anyone is accountable on the other end.

Sources