who said anything about vpn? vpn is generally an rsa encrypted channel.
im talking standard gprs/3g/hsdpa
each device on the data carrier is connected from a dhcp pool from a sgsn/ggsn and given an ip from a range within that subnet
certain ports have to be open for data transit to work
potentially (i have no actual factual information so cannot fully confirm) someone within that same subnet/iprange can connect a device to the network and find plain text being transmitted from these ports.
imo if you use your providers data network you have just as much reason to be concerned as someone using adhock/unsecured wifi nodes