1) Guy leaves token'd doc on WebServer (not in document root)
2) Token is hit from Russian IP Address.
Seriously use https://canarytokens.org