YC-backed Cymmetria published a report about an APT caught with cyber-deception
threatpost.com
threatpost.com
1. Honeypots are easy to fingerprint (see our blackhat talk, https://www.youtube.com/watch?v=Pjvr25lMKSY )
2. Most honeypots just "sit on the network", waiting to be scanned. By using breadcrumbs (AKA honeytokens) as part of deception stories you're actively hunting the attackers in the network, by influencing their decision process.