https://arstechnica.com/information-technology/2017/12/nope-...
For ~$170 apparently you can get an EV cert for "Stripe, Inc" (by forming a company with that name).
Even aside from that fact, users are very bad at knowing what a secure site looks like. I would wager that if most users clicked "login" and didn't see an EV cert, but instead saw "<padlock> Secure" (i.e. a non-EV HTTPS connection), they would not notice the difference.
Troy is right to kick up a fuss about this; this is a significant attack vector (anyone on a wifi network can MITM your banking login URL), and it's more egregious because of how easy it is to set up HTTPS.