From IRC: Apparently $someone intercepted XMPP traffic to jabber.ru (hosted by Hetzner and Linode in Germany) with a middlebox, and this was detected only because the Let's Encrypt certificates used for the interception ran out: https://notes.valdikss.org.ru/jabber.ru-mitm/
This kind of attack is not usually possible without cooperation from the hosting provider, quote: "We believe this is lawful interception Hetzner and Linode were forced to setup."