A honeytoken is a deliberately planted piece of bait that does nothing useful except report when it is touched. It might be a document that phones home when opened, a fake login that alerts on use, or a unique tracking link. Because a legitimate user has no reason to interact with it, any access is a strong signal that someone is snooping.
Honeytokens cut both ways in OSINT. Defenders and privacy-conscious people use them to detect when their data is being probed or when a leaked file is opened. Investigators, in turn, must assume that documents, links, and images they encounter could be honeytokens — opening one on an attributable device can reveal your IP, location, and the fact that you are watching. It is a core reason to work from an isolated environment.