Argument 1: this person was able to get an EV cert for "Stripe, Inc. [US]", an entity they registered in Kentucky, no relation to the Stripe, Inc. of California whose website is stripe.com. They were not able to get a certificate for stripe.com. (The CA revoked it, and then later apologized for revoking it because there was no reason by their policy to do so.) https://stripe.ian.sh/
Argument 2: the actual website for MasterCard's SecureCode is https://www.mycardsecure.com/ , whose EV cert is "Arcot Systems LLC [US]". The fact that it has a meaningless domain name is in no way fixed by it having a meaningless (but technically accurate, Arcot is the contractor for SecureCode) EV cert. How do you know you're actually supposed to type your personal information there?
Argument 3: the web's security model is based on origins (domain names), not on EV certs. If Stripe switches tomorrow to stripeiscool.com and a domain squatter gets stripe.com, my browser will still send cookies to stripe.com, even though it no longer has an EV cert, and it certainly won't send cookies to stripeiscool.com, even if it has an EV cert with the same organization. Even if EV were a good idea in the abstract, it lacks a plan to make it work with the web as actually deployed.