that sort of thing has happened. it's been documented to happen to www.microsoft.com and there's no reason to believe that it can't happen with a bank as well.
but if you watch out for the cert changing, as opposed to just the cert existing, you cover most of that problem