It might be plausible that the CA issued the subsidiary CA cert to a government agency due to incompetency, it is very hard to chalk it up to a 'mistake', if that said government agency uses the accidentally issued CA cert on their SSL intercepting firewall. What a convenient accident...