Here's the truth about security: people are clueless about it and so corporations and governments abuse that by pushing their own agendas, not related to security. Same corporations that tell you to "secure" your unimportant static website with https also want to force you to run random javascript in your browser from unknown parties, identify you at all times, link everything to your phone number, etc. In the end we…
How are those related? Letsencrypt doesn't try to identify anyone, and certainly doesn't run JavaScript on your site.
If you understand human behavior, then you know that this WILL happen eventually.