In theory it is possible. In practice I don't know that there are any recorded instances outside NSA. I've read that there are no known cases of credit card numbers being harvested from plaintext IP traffic.
Your question should really be directed to your employer or the customer.
If you're on an Intranet I would forget about it; if you're using the Internet it may be required to use SSL.