The feds have already pulled a similar stunt with another manufacturer+software combo. (https://en.m.wikipedia.org/wiki/Operation_Trojan_Shield#Distribution_and_usage)
The only thing that makes this smell legit is the fact that it is a provider and probably only eSIMs. But even then, this is not very good opsec to be deliberately using a marketed product that will likely have an identifier for their cell traffic. Graphene works as well as it does because it runs of pre-existing hardware to be more inconspicuous.