As a U.S.-based organization we are required to comply with U.S. law. As such, we cannot provides services to people, organizations, or websites listed on the U.S. Treasury Department’s Office of Foreign Asset Control (OFAC) Specially Designated Nationals (SDN) list.
When it is brought to our attention that we are serving an entity on the SDN list, and if we can confirm the report, we will respond by revoking outstanding certs and banning future issuance to the entity.
That is what happened here - it was brought to our attention (not by a government agency or official) that we served usareally.com 39 and that it was now on the SDN list so we revoked and banned.
This happens to maybe one domain per month, to give you some idea of the frequency.
https://www.mcclatchydc.com/news/policy/technology/cyber-security/article223832790.html :
Treasury described USA Really as part of a broad Russian campaign “to interfere in political and electoral systems worldwide,” adding that some of the actions were under the direction of Yevgeniy Prigozhin, a friend of Putin who was one of the sponsors of a Russian “troll factory” accused of meddling in 2016 U.S. elections.
C'est pour ça que j'ai toujours mis en garde contre une utilisation irréfléchie ("c'est gratuit ! et automatique" ‒ CAcert et les AC dotées d'API apprécieront ‒) et hégémonique de Let's Encrypt. Une autorité de certification (AC) est un tiers supplémentaire qui peut censurer un service Internet (en sus de l'hébergeur, du registre DNS, etc.), surtout depuis que le chiffrement est devenu obligatoire. Bien sûr, ce n'est pas dramatique, en cas de censure, on change d'AC et basta, la panne dure quelques heures. Mais, à l'échelle globale, cela retarde le déploiement de solutions techniques moins foireuses (DANE TLSA, par ex.).