quantcast was sued for resuscitating browser cookies when flash LSOs persisted [1], ie taking the cookie value from the LSO and recookie-ing the browser. quantcast and clearspring settled for $2.5m [2]. The crux of the matter seemed to be that users didn't know such data was in flash cookies or associated with quantcast, making it hard to opt-out, though I'm not sure if this is illegal; and violated quantcast and the 3rd party sites' privacy agreements, which appears to be illegal. A lawsuit outline for one plaintiff is here [3] and the full text of the initial filing here [4]. I naively assume there is a clear parallel to this case, though perhaps verizon and turn have thoroughly privacy policied their way out, somewhere in 30 pages of legalese.
According to Jonathan Mayer,
Commercial supercookies, fingerprinting, and zombie cookies are tolerated
(if not permitted) under current United States law. [...] Any associated
consumer deception, however, is a violation of the Federal Trade Commission
Act and parallel state statutes. [5]
[1]
http://www.wired.com/2010/07/zombie-cookies-lawsuit/[2] http://www.lexology.com/library/detail.aspx?g=bc3a4358-6692-...
[3] https://www.privaworks.com/Details/AlertReference/PrintPrevi...
[4] http://www.wired.com/images_blogs/threatlevel/2010/07/CV10-5...
[5] http://webpolicy.org/2015/01/14/turn-verizon-zombie-cookie/