@tony Usually it means they finally started looking at their firewall logs for the first time. And they misinterpret every port scan as an active attack.