Law / United States / Kentucky

Kentucky Unlawful Access to a Computer

KRS 434.845 to 434.855

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 15 July 2002.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not access, cause to be accessed, or attempt to access a Kentucky-connected computer, computer system, computer network, or the data or software on one, without the effective consent of the owner.
  • Consent obtained by deception or coercion, or given by a person not authorized to act for the owner, is not effective consent, so deceptively circumventing a login, paywall, or other technical access control falls within this statute.
  • Access made without effective consent is criminal even where it causes no loss or damage; access causing loss or damage of $300 or more is a felony, and access made to defraud or to obtain money, property, or services is the most serious tier.
  • Do not receive, conceal, or use data or property known to have been obtained through a violation of this statute; doing so is a separate felony.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Kentucky grades unauthorized computer access by degree: a Class C felony where the access is made to defraud or to obtain money, property, or services (KRS 434.845); a Class D felony where the access, without that purpose, causes loss or damage of $300 or more (KRS 434.850); a Class A misdemeanor where the loss or damage is under $300 (KRS 434.851); and a Class B misdemeanor where the access causes no loss or damage at all (KRS 434.853). Receiving or using the proceeds of a KRS 434.845 violation is a separate Class C felony (KRS 434.855, misuse of computer information).

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Kentucky makes it unlawful to access, cause to be accessed, or attempt to access a computer, computer system, computer network, or any data or software on one, without the effective consent of the owner, and grades the offense in four degrees. Access made to defraud or to obtain money, property, or services is a Class C felony (first degree). Access without that purpose that causes loss or damage of $300 or more is a Class D felony (second degree).

Access causing loss or damage of less than $300 is a Class A misdemeanor (third degree). Access causing no loss or damage at all is still a Class B misdemeanor (fourth degree), so the statute does not require any resulting harm to establish criminal liability, only the absence of effective consent. Separately, knowingly receiving, concealing, or using data or property obtained through a first-degree violation is its own Class C felony (misuse of computer information).

Effective consent is defined at KRS 434.840 and is not effective when induced by deception or coercion or given by a person not authorized to act for the owner, so deceptively circumventing a login, paywall, or other access control falls within the statute regardless of which degree applies.

The statute's text does not expressly except ordinary, unauthenticated access to a publicly available page, and no Kentucky court decision construing the without-effective-consent standard as applied to automated collection of public web content has been located.

When LexLint raises it

  • crawls_web

Read the law

official text, Kentucky Revised Statutes (KRS 434.840 to 434.860)

Back to the example  ·  Lint your app