I know someone who got caught out by this. Bank's front page was http, so the attackers mitm'ed that. Ebanking link was swapped out for an https page they controlled, allowing the credentials to be harvested before redirecting to the bank.
When you first access a site, unless the site is using HSTS you are going to go to an insecure version so a mitm can proxy the request and remove tls or redirect you to another site. This is what is known as "https stripping."
HSTS helps unless you are always on compromised networks or the site uses short TTLs. Even without preloading most people are probably not accessing their bank for the first time ever on a malicious network.