A mitm faking a wifi hotspot can pretend to be bunq and transparently forward the traffic to the real bunq platform and back to the client. I don’t know exactly how much you can see that way, but more than just the bandwidth usage. At least you can track devices that talk to bunq. Combined with non-bunq traffic you may find the person and other gifts. There is so much more to a person than just their money.
Using VPN is rarely a bad idea; unless you choose a (paid) service that you can’t control yourself, which is all of them. Those are only useful to hide your home IP from the sites you visit. Expect them to look into your traffic, even when they promise not to.. At the moment running your own VPN service from home or your own server/vps is pretty much the only way to protect your traffic a bit more than just streaming raw data over the air. However, all software is buggy including the TLS libs everyone is using to encrypt the traffic. Just because there may not be any reports that doesn’t mean the software is completely secure. Nothing is.
Sorry to be so grim, here‘s a shot of happy: ☀🍀😛