Was your sniffer set to listen on all interfaces? More than likely, you just saw some broadcast traffic from your PPTP (or whatever your using) VPN tunnel you had to work. If you specifically directed your attacks to a specific subnet, they stayed on that sunbet. Of course, I don't know exactly what your using. (backtrack?) Your probably cool @ work. If not, flush your arp table, & move on. I wouldn't even tell anyone. Or, just wait. Once the ARP poisoning is over the clients will sort themselves out in time.