These subdomains/sites are most likely misconfigured in such a way that malicious actors are able to redirect to/host anything they wish.
There was a blogpost here on HN about this, showing that (Roblox/Robux) scams were also seemingly hosted on .gov sites. I can't find that post anymore.
Here is a publication related to what you've found: https://cofense.com/blog/threat-actors-exploit-government-we...