It might be a case where illegal / scam / anything of that type were using the SSLMate service to issue and deploy those certificates, whereas some aspects of this process (DNS / HTTP / Mail) verification or similar were processed directly on the GCP.
I could not get from the OP what really happened and what was the claim / explanation from Google side.
If scammy GCP users use SSLMate, then GCP should probably ban the scammy users instead of SSLMate?
Google said "general terms of service violation" or unspecified "abusive activities". Google is only involved in the publication of DNS records, not the deployment of certificates. Note that they didn't require us to take any action after the suspension in 2024 to correct this alleged abuse; they just re-enabled access without any further explanation.