This email address harvesting process is a primary reason to never use your favorite/main address for anything but business purposes or a select group of friends. Get as many aliases from whoever your ISP is and use those for registering at public sites (forums, stores, etc.). These aliases should be free, of course. You can probably get (or have) some from DOTmac, DOTme and/or iCloud. It might be worth signing up for Gmail just for the disposable addresses. TMMV!
The above will NOT keep your main/favorite address from being harvested, however. Anyone who gets a message from you and has a less than secure Windows machine (I've heard there are a few of those are still around!), can certainly be invaded and their Address Book harvested. And, if someone included your favorite/main address in either the
TO: or
CC: field of a message, anyone on
THAT group can have your addy harvested. That is why
BBC: is the best place to include multiple addresses; other recipients will not see yours.
Once you have had an address harvested (added to a list that gets passed around or even sold), it may be pointless to keep using it. Hopefully, it will be an alias and you can simply delete it and create another. If it is your favorite/main addy, you may want to try waiting until the Internet creatures die or get tired of using it. That may be an extremely long time, close to the half-life of Plutonium, probably.
There are places/sites/agencies where you can report SPAM but I'm not sure they accomplish anything of value and this is not actually SPAM coming to you, it's just SPAM purporting to come from you! Even worse, in my opinion!
It might be nice of you to send emails to anyone who uses that addy and warn them not to click on that link, of course. It also may be too late...