I notice the victim uses Android: Is it rooted? What other random stuff do they have installed? etc. etc. - because that will make a huge difference.
Money can't be "stolen" from your Uber account.
Someone can find out your password to your Uber account the same way they could get your password for any website. Then they log in as you, and take trips using your account. Your card would then be charged for the trips.
It's OP's fault that someone found out their password. Uber was nice and refunded them for the trips.
Except the account in the article had two factor auth enabled. Someone triggered the second factor (a text message) then logged in without access to it. That's the question at the heart of "how did this attack happen?"
It is certainly possible that Uber's TFA system is compromised, but that's not the only explanation.