I used to have internet from Cox Communications. One day when I was working from home, I was surprised to see a page in my local dev environment load with an overlay telling me my ISP thinks I have a Windows virus (I didn't own any Windows machines at the time).
Turns out our dev environment didn't force CDN assets to load over HTTPS, so my ISP injected some JS into a library we were loading.
I tweeted at them, and they not only verified that it came from them, but also that they consider hijacking and modifying my traffic to be a service.