I guess that it's even easier to sniff upstream traffic (to/from VPN endpoints) to such small internet outposts than, let's say AWS, Akamai or any other large infrastructure provider out there.
This. You're at the mercy of their upstreams, which are fixed, targets for TLAs, and likely to be sharing the pipes with other people who are (at least in their own eyes) high value targets.