They're not obvious attacker certs, but Ralph Holtz has found some very strange certs in S. Korea with SN:"Government of Korea" and CA:TRUE. http://www.mail-archive.com/cryptography@randombit.net/msg01...
Also, it's not clear that this is "run of the mill law enforcement". This is NIS, the S. Korean state intelligence service, which is admitting to having done this.
"First rule of State-run CA Club is...