Considering they have the plaintext passwords and that Uber can't identify a breach, it's most likely people who re-use the same password and were a victim of another hack (adobe et al.)
If this was due to a breach at Uber, it stands to reason there would be millions of accounts for sale, not merely thousands. I'm more inclined to believe this is a result of shared and/or weak passwords.