Hi @Ravi_Akkiraju ,
Please note the information under the Auth API section in the following KB article: Knowledge Base | Duo Security
The attacker can make Auth API calls to retrieve the phone number for any user – however all but the last four digits are obfuscated (example: XXX-XXX-1234). This is limited risk, but phone numbers are sometimes considered sensitive information.
From an administrative perspective, you can use the Admin API to view a Duo user’s entire phone number.
Hope this helps!