As per Hikma audit, Bots can check and validate the valid email address and phone numbers, which can give access to personal customer information. we have to not only mask on UI but also make sure that Bots can't validate the customer personal information from pages like Forgot password etc.
Mask the email and show only the first 2 characters and the domain name
Mask the phone number and show only last 3 digits