Establish contractual damages in a ToS for the site. Prove violation and offender. Take to court and collect damages.
Converting the effort into cash is tough, but the strategy exists.
Project HoneyPot is an API which allows any website to do this for honeypot email addresses which are injected the website, along with a ToS which says:
> By continuing to access the Website, You acknowledge and agree that each email address the Website contains has a value not less than US $50 derived from their relative secrecy.[1]
I also found the $1 billion lawsuit (against a bunch, not just one spammer, I believe), and could also not find any sort of resolution - not in legal docs, news pages, or project honeypot itself.
Converting the effort into cash is tough, but the strategy exists.
Project HoneyPot is an API which allows any website to do this for honeypot email addresses which are injected the website, along with a ToS which says:
> By continuing to access the Website, You acknowledge and agree that each email address the Website contains has a value not less than US $50 derived from their relative secrecy.[1]
[1] https://www.projecthoneypot.org/terms_of_use.php