On the defender side, it's much funnier to poison the data of identified scrapers than to immediately ban them. Let them work out that their data has been altered for a while, clean up their datasets, and work to understand what identifies them as scrapers.
Definitely, but it's also a lot more complex to present credible looking false data than to simply reject a request.