It might be a case where illegal / scam / anything of that type were using the SSLMate service to issue and deploy those certificates, whereas some aspects of this process (DNS / HTTP / Mail) verification or similar were processed directly on the GCP.
I could not get from the OP what really happened and what was the claim / explanation from Google side.