You can put up ToS all you want. I'm not agreeing to your terms by visiting your website (I'm not even visiting the site, my scraper is. Can a scraper sign a contract? I doubt it). Maybe law is f'd up like that in the US. Is it? Fine, I'll buy servers in Russia. Or some banana republic. Come sue me in the wonderful state of Nevis and see how that goes.
You can do a lot to prevent it. The best way to prevent it is to not have valuable data. The more valuable your data, the more effort we will spend on cracking your countermeasures and we will always win because this is our core business - to you its just a cost center.
Linkedin is one of the most notorious sites for trying to prevent scraping and they certainly have the funds. Yet they can't do shit about it and you'd think that they have it easy because they hide everything behind a paywall. Yet they can't prevent it from happening. Not even close. If they can't do it, you probably can't either.
And that's the really boring part. Do you know how many blank APIs there are in the web? People do their node.js and their frontend SPA bs and then they just dangle an API that is open for the world to scan. I could make a business out of scanning for exposed user data and feed them into a lawyer doing class-action lawsuits all day. Would be easy. Like really easy. So-called "engineers" need to learn how cryptography works. Or just reject unauthorized requests. Its really not that difficult.
To call out one prominent example: The Tinder API has been exposed ca. 2012 and ever since then, they didn't give enough of a shit to secure it. You can still build a tinder 3rd party app using their api.