$re = '`\b(\d{4})\d{6}\b`m';
$str = 'arandomsensitive information: 1234567890 this is not senstive: 1234567890000000';
$subst = "$1******";
$result = preg_replace($re, $subst, $str);
echo "The result of the substitution is ".$result;
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for PHP, please visit: http://php.net/manual/en/ref.pcre.php