Because the domain they are accessing is difference from the one in the certificate. For example, they are accessing www.example.com but the certificate says myonlinebank.example.com. The wildcard certificate will allow this because the subdomain can be anything. The non-wildcard certificate requires the names to match exactly.