The short answer is that Ohio’s pandemic unemployment operation did not always make a worker’s technical permissions match the worker’s actual authority.
The Justice Department says Joirean Creel and her sister, Adriane Creel, were hired as remote teleservices representatives whose system access was supposed to support customer service by phone. Yet prosecutors say they used that access to nullify or void claims that had already been held or denied as suspected fraud—even though they were not authorized to do so. The resulting payments totaled about $1.96 million. The sisters pleaded guilty on August 31, 2026. (Department of Justice)
Ohio’s own records help explain how that could happen. In a separate investigation, the Ohio Inspector General found that temporary unemployment workers who were not authorized to reverse certain claim decisions could nevertheless perform those actions because the applications used to process Pandemic Unemployment Assistance claims did not technically stop them.
And that was not the only access-control problem Ohio documented. In other cases, unemployment contractors retained usable system credentials after their employment had ended, including one worker who continued manipulating claims for three months after being fired.
Those records do not prove exactly which technical or administrative failure applied to Joirean Creel’s account. But they establish something more important than speculation: both excessive functional access and failed account deactivation occurred in the same Ohio pandemic unemployment environment.
What Joirean and Adriane Creel pleaded guilty to
Joirean Creel, 35, of Duluth, Georgia, and Adriane Creel, 24, of Stone Mountain, Georgia, pleaded guilty to conspiracy to commit wire fraud and honest-services wire fraud. U.S. Magistrate Judge Jonathan D. Greenberg accepted the pleas on August 31, according to the U.S. Attorney’s Office for the Northern District of Ohio. (Department of Justice)
DOJ says both women had been hired through an unidentified subcontractor to work remotely for the Ohio Department of Job and Family Services, or ODJFS, as teleservices representatives.
Their jobs gave them access to an online system used to process and manage unemployment claims, but DOJ says that access was supposed to be used for their customer-service work with claimants by phone.
According to the factual allegations DOJ attributes to the court documents, the sisters instead solicited and accepted bribes or kickbacks to intervene in claims that had already been flagged, held or denied because of suspected fraud. They allegedly used their accounts to nullify or void those issues, causing approximately $1.96 million in benefits to be paid. DOJ says the conspiracy caused ODJFS more than $2 million in total losses. (Department of Justice)
The government also says the sisters fraudulently sought unemployment benefits for themselves in other states, including New York, Pennsylvania and Nevada. Investigators found that Joirean was employed by the U.S. Postal Service while claiming unemployment, according to DOJ. A Mercedes-Benz GL450 was seized and forfeited during the investigation. (Department of Justice)
The guilty pleas are established. For the more detailed description of how individual claims were manipulated, DOJ still characterizes its account as allegations contained in court documents. That distinction matters until the underlying plea agreements or factual stipulations are publicly available.
“Not authorized” is different from “the system will not let you”
The central technical issue is simpler than it sounds.
An employer can control a worker in two different ways:
Administrative authorization: The employee is trained and instructed not to perform a particular action.
Technical authorization: The software itself refuses to let that employee perform the action.
Good access control tries to make those two things match.
For example, if a call-center worker is allowed to view a claim and explain its status but is not allowed to adjudicate eligibility, the safer design is not merely to train that worker not to press the adjudication button. The account should not have the permission necessary to perform the adjudication at all.
That principle is often called least privilege: give each user only the access required to perform that user’s job.
Ohio’s Inspector General found that this separation broke down in the pandemic unemployment operation.
Ohio investigators found workers could make decisions they were not authorized to make
A February 2023 Inspector General investigation into temporary customer-service representative Deanna Rooney produced the clearest finding.
Investigators determined that after a PUA claim had been found ineligible and assessed an overpayment, only temporary workers assigned to appeals or redetermination teams were authorized to change the claim back to eligible.
But other intermittent and contract workers could still make that change.
The Inspector General said employees who were not assigned to those teams and were not authorized to make the determinations nevertheless retained the technical ability to do so because the PUA applications “did not prevent them from executing these tasks.”
Investigators identified three possible consequences of that arrangement: inadequate training could produce improper actions, ordinary mistakes could produce them, or a worker could intentionally exploit the access to fraudulently eliminate an overpayment.
That finding answers a major part of the question raised by the Creel case.
A rule saying “customer-service workers may not do this” did not necessarily mean the underlying applications had been configured so that “customer-service workers cannot do this.”
What workers were authorized to do vs. what Ohio records show was technically possible
| Action | Within ordinary call-center/CSR authority? | Documented as technically possible in Ohio PUA cases? |
|---|---|---|
| Answer claimant questions and assist with claims | Yes | Yes |
| Reverse an ineligible claim through redetermination | Restricted to designated personnel | Yes |
| Adjudicate an issue that could trigger payment | Restricted | Yes |
| Void fraud or identity-verification issues | Not authorized for the CSR documented below | Yes |
| Continue using unemployment-system credentials after employment ended | No | Yes, in multiple documented cases |
These examples come from several Ohio investigations; the table should not be read as a description of the exact permissions assigned to the Creel sisters.
Another Ohio customer-service worker actually voided fraud issues without authority
The closest documented comparison to the Creel allegations involves former customer-service representative Renita Carr.
ODJFS referred Carr for investigation after reviewing her activity in the pandemic unemployment system. According to the Inspector General, Carr had improperly searched for particular claimants and performed actions including:
- voiding fraud issues;
- voiding program-eligibility issues;
- voiding identity-verification issues;
- removing fact-finding information from fraud issues; and
- voiding employment-verification requirements.
ODJFS identified 28 claims in which Carr’s improper actions resulted in benefit payments. The Inspector General concluded those actions caused $565,949 in PUA funds to be fraudulently released. Investigators said Carr was not authorized to perform the relevant actions.
That is unusually important context for the Creel case.
DOJ now says the Creels were teleservices workers who nullified or voided suspected-fraud claims despite lacking authority. The Carr investigation independently demonstrates that an Ohio customer-service worker could, in fact, reach claim functions capable of voiding fraud and eligibility controls despite not being authorized to use them that way.
The cases are not necessarily technically identical. The government has not publicly identified the exact transaction codes used by the Creels or even named their unemployment application in its September 3 announcement.
But the broader mechanism is not hypothetical.
Could a fired Ohio unemployment contractor’s login really keep working?
Yes. Ohio has documented that happening.
The clearest example is Andrew Kerobo.
Kerobo was a remote seasonal teleservices representative employed by Randstad and supervised through Harte Hanks while working on Ohio PUA claims. His job was taking inbound calls from claimants. According to the Inspector General, he had no authority to adjudicate issues that could cause a payment to be released or blocked. (Cloudinary)
Kerobo’s employment ended on September 5, 2020.
His credentials did not.
The Inspector General found that his unemployment-system login was not deactivated and that Kerobo continued entering the system and manipulating claims until December 10, 2020.
Investigators attributed 435 manipulated claims and $6,827,460 in fraudulent payments specifically to the 90-day period after his termination. Altogether, the investigation attributed 448 manipulated claims and $6,864,263 in fraudulent releases to his activity before and after termination.
Kerobo later pleaded guilty in the resulting Ohio prosecution and was sentenced in April 2026 to a minimum of seven years and a maximum of 10½ years in prison. (Cloudinary)
So the broader question—could a terminated Ohio unemployment call-taker really continue accessing the claims system?—does not require speculation.
It happened.
Another contractor was fired in August. Her access was not terminated until the following June
The case of Janelle Thrower-Rivera exposes the offboarding problem even more clearly.
Thrower-Rivera was employed through Randstad, which supplied workers through Harte Hanks under the larger Deloitte PUA operation.
She was terminated on August 12, 2020. Harte Hanks notified Deloitte of the termination on August 19.
Deloitte told investigators her last login occurred on September 9, 2020.
Yet records reviewed by the Inspector General showed Deloitte did not terminate her PUA-system access until June 7, 2021—nearly ten months after she lost the job.
That does not mean she continued logging in for all ten months. The report says her final login was in September.
But it demonstrates an important distinction:
Firing a worker and disabling the worker’s technical access are separate events.
An HR or staffing company can end a job immediately while the associated application account remains provisioned until someone else completes the technical deactivation.
In a multilayer contractor environment, that handoff matters.
The contractor chain itself created another control boundary
Ohio’s pandemic unemployment program relied heavily on outside workers because of the enormous volume of claims.
In the Kerobo investigation, the documented chain looked like this:
ODJFS → Deloitte → Harte Hanks → Randstad → individual call-center worker
Deloitte contracted with ODJFS to assist with PUA administration. Deloitte contracted with Harte Hanks for staffing, and Harte Hanks in turn used Randstad to supply workers.
That does not establish that the Creels worked through the same companies. DOJ has not publicly identified their subcontractor, and it would be wrong to infer one from unrelated cases.
But it illustrates why offboarding could become a control problem.
The organization that knows an employee has been terminated is not necessarily the organization controlling the unemployment-system account. Employment status has to reach whoever manages the technical identity, and that identity then has to be disabled in every relevant system.
Kerobo and Thrower-Rivera show that this process sometimes failed.
What do we actually know about Joirean Creel after she was fired?
This is the part of the story that requires the clearest source distinction.
Secondary reporting based on federal court records says the sisters were hired about a week apart in February 2021 and that Joirean was fired in March. That reporting says her own credentials continued working for weeks after termination, that she modified 145 claims after being fired, and that she later used Adriane’s credentials as well. (Hoodline)
Those are significant allegations, but sherafy.com was unable to independently retrieve the underlying charging document from the publicly indexed federal court sources reviewed for this article.
The Justice Department’s September 3 guilty-plea announcement confirms the broader unauthorized-access scheme, but it does not specify Joirean’s termination date, the 145-claim figure, how long her personal credentials remained active or when they were finally disabled. (Department of Justice)
So the evidence should be separated this way:
Verified from primary records: Ohio had documented cases where fired unemployment contractors retained usable system access.
Reported from the Creel court filings: Joirean allegedly continued using her credentials after being fired and modified 145 claims afterward.
Still unknown publicly: who was responsible for disabling Joirean’s account, when that account was actually deactivated and which contractor employed the sisters.
The institutional story does not depend on assuming answers to those questions.
Ohio did have fraud controls and detailed audit logs
The evidence does not support saying Ohio’s pandemic unemployment system had no security controls.
That would be too broad.
The state auditor documented fraud indicators, adjudication procedures, supervisory review and a daily Fraud Dashboard used by Benefit Payment Control personnel. The audit also tested samples of uFACTS fraud-processing controls. (Ohio Auditor)
Separately, the Carr investigation shows that uFACTS maintained a detailed audit trail. It recorded access to claim files, alterations to claim information, claim searches and the identity of the person performing the activity.
Those records eventually made forensic reconstruction possible.
But logging an unauthorized action is not the same thing as preventing it.
And maintaining a detailed audit trail is not necessarily the same as generating a useful real-time alert when, for example:
- a customer-service representative starts performing adjudicator functions;
- one worker repeatedly voids fraud issues on unrelated claims;
- a terminated account successfully logs in; or
- an employee accesses an unusual number of claims outside ordinary workflow.
The records reviewed for this article do not establish what real-time user-behavior alerts existed or whether any such alerts fired in the Creel case.
That remains one of the most important unanswered questions.
Some payment controls did stop unauthorized actions
There is another reason not to describe the Ohio system as entirely unprotected.
In the Thrower-Rivera investigation, unauthorized actions did not always result in money being released. Investigators found that some claims still contained other unresolved issues, preventing payments despite attempted manipulation. (Cloudinary)
In other words, there could be multiple barriers between a questionable claim and a payment.
That actually sharpens the relevant failure.
The remarkable part is not that every low-level worker had a universal “pay claim” button. The records do not support that.
It is that workers whose assigned jobs did not authorize consequential adjudication functions could nevertheless reach at least some of those functions at all.
The state auditor had separately raised concerns about oversight of uFACTS
The access-control cases occurred within a pandemic system that had been deployed under extraordinary pressure.
Ohio’s older unemployment platform, OJI, could not handle the surge in applicants. Effective May 14, 2020, ODJFS contracted with Deloitte for key pandemic unemployment processing through an outside system known as uFACTS.
The Ohio Auditor reported that approximately $8.07 billion in pandemic benefits passed through uFACTS during the period it examined. Deloitte’s responsibilities included system design with ODJFS input, training and security, software hosting, call-center management and reporting. (Ohio Auditor)
The auditor also found that ODJFS had not established sufficient procedures to determine whether the service organization’s controls were adequately designed and operating effectively and had not obtained the relevant SOC 1 Type 2 assurance for uFACTS. The auditor recommended stronger monitoring of the service organization and independent assurance over its controls.
That finding is relevant context, but it should not be stretched beyond what the audit proves.
The state audit did not find that the missing assurance caused the Creel scheme.
It instead shows that Ohio had a broader governance problem: the state was relying on an outsourced system handling billions of dollars without obtaining the level of independent control assurance the auditor believed was necessary.
What Ohio says it changed afterward
After the Inspector General documented workers performing functions outside their authorized roles, it recommended that ODJFS develop safeguards preventing employees and contractors from exceeding the scope of their training and authority.
ODJFS responded in April 2023 that it was continuing to develop and review such safeguards.
The department said that, with PUA ended, it was applying the recommendation to Ohio’s traditional unemployment system, where access was limited by assigned role. ODJFS said that system had 41 possible roles and that each user could be assigned only one. It also reported additional supervisor training and a team tasked with examining suspicious employee activity.
That is evidence of a response to the problem.
It is not evidence that the same 41-role architecture governed the PUA accounts used in 2020 and 2021, and it does not establish that every underlying access-control weakness has since been eliminated.
Was this an ODJFS failure, a contractor failure or employee fraud?
The evidence supports all three categories at different levels, but it does not justify assigning every failure in the Creel case to one organization.
The deliberate wrongdoing is straightforward: Joirean and Adriane Creel have pleaded guilty to federal fraud charges.
The institutional weaknesses are also documented:
- Least-privilege failure: Ohio’s Inspector General found temporary workers could perform restricted decisions because applications did not prevent them.
- Offboarding failure: Kerobo and Thrower-Rivera show that unemployment-system access was not always promptly terminated when employment ended.
- Oversight weakness: Ohio’s state auditor found inadequate assurance over controls in the outsourced uFACTS operation.
- Detection versus prevention: uFACTS kept detailed audit records, but those records did not necessarily prevent an unauthorized transaction from occurring.
What remains unresolved is how those pieces map onto the specific Creel accounts.
The public records reviewed here do not identify their subcontractor, their precise system roles, the technical date Joirean’s credentials were deactivated or the organization responsible for that deactivation.
The best-supported conclusion
The Creel case is more accurately understood as an insider-access case than a conventional computer “hack.”
There is no public evidence that the sisters discovered a software vulnerability, bypassed authentication or broke into a system from the outside.
Instead, DOJ says they abused legitimate system access they received through their jobs.
Ohio’s own investigations then supply the missing context: during the pandemic unemployment operation, job authority and technical capability did not always match. Workers who were not authorized to perform certain claim decisions sometimes could perform them anyway. And in separate cases, credentials remained usable after the worker’s employment ended.
That does not transfer responsibility away from employees who deliberately exploited their access.
It explains why the opportunity existed.
The unanswered Creel-specific question is no longer whether Ohio experienced these types of failures. It demonstrably did.
The remaining question is which combination of excessive permissions, failed offboarding, contractor oversight and insufficient real-time detection allowed this particular scheme to continue long enough to produce nearly $2 million in payments.
Frequently Asked Questions
Were Joirean and Adriane Creel authorized to remove Ohio unemployment fraud holds?
DOJ says no. Prosecutors say their system access was intended for telephone customer-service work and that they nullified or voided suspected-fraud claims despite not being authorized to do so. (Department of Justice)
How could a customer-service worker change a claim anyway?
Ohio’s Inspector General documented that some temporary PUA workers outside authorized appeals and redetermination roles still had the technical ability to make restricted decisions because the applications did not block them. A separate investigation found a customer-service representative voiding fraud and verification issues she was not authorized to perform.
Did Joirean Creel continue accessing the system after she was fired?
Reporting based on federal court records says she did and says she modified 145 claims after termination. The public DOJ announcement does not include those details, and sherafy.com was unable to independently retrieve the underlying charging document from publicly indexed sources reviewed for this article. (Hoodline)
Did other fired Ohio unemployment contractors keep system access?
Yes. Ohio’s Inspector General found that Andrew Kerobo continued logging in and manipulating claims for about three months after his termination because his credentials had not been deactivated. In another case, Janelle Thrower-Rivera’s final login came weeks after her termination, while records showed her technical access was not formally terminated until months later.
Did Ohio fix the problem?
ODJFS said in 2023 that it was developing safeguards to prevent employees and contractors from exceeding their authority and applying the recommendation to the traditional unemployment system, where accounts were restricted according to assigned roles. The available evidence does not establish that every access-control or contractor-offboarding problem has been eliminated.
References and Further Reading
Federal Creel case
U.S. Attorney’s Office — “Georgia Sisters Plead Guilty to Roles in $2M Pandemic Benefits Fraud Scheme” — Primary federal source confirming the Creels’ guilty pleas, customer-service roles, unauthorized nullification of suspected-fraud claims, $1.96 million in resulting payments and more than $2 million in total ODJFS losses.
U.S. Department of Labor Office of Inspector General — Creel investigative update — DOL-OIG’s announcement of the federal case; largely mirrors DOJ but confirms DOL-OIG’s investigative role.
Hoodline — “Cleveland Sisters Took Bribes to Approve $1.9M in Fake Jobless Claims, Feds Say” — Secondary reporting citing federal court records for the additional claim that Joirean continued accessing the system after termination and modified 145 claims. Those specific details are treated as attributed reporting rather than independently verified primary facts here.
Ohio Inspector General: permissions and unauthorized actions
Ohio Inspector General Report 2022-CA00004 — Deanna Rooney investigation — The strongest primary source on the policy-versus-permission gap. Investigators found workers who were not authorized to redetermine claims could technically do so because the PUA applications did not prevent the actions.
ODJFS response to Inspector General Report 2022-CA00004 — ODJFS’s April 2023 response describing safeguards, role-based access in the traditional unemployment system, supervisor training and suspicious-activity review.
Ohio Inspector General Report 2021-CA00018 — Renita Carr investigation — Documents a customer-service representative improperly voiding fraud, identity-verification, employment and eligibility issues, resulting in $565,949 in PUA payments.
Ohio Inspector General: post-termination access
Ohio Inspector General Report 2023-CA00011 — Andrew Kerobo investigation — Documents a terminated call-taker whose credentials remained active for roughly three months, allowing continued unauthorized claim manipulation after employment ended.
Ohio Inspector General Report 2023-CA00008 — Janelle Thrower-Rivera investigation — Documents the separation between employment termination, contractor notification, last system login and eventual technical deactivation of PUA access.
System and oversight
Ohio Auditor of State — Auditor’s Report on Unemployment Insurance Fraud, March 2020–February 2021 — Primary audit describing the uFACTS architecture, Deloitte’s responsibilities, approximately $8.07 billion processed through the system, fraud controls and deficiencies in ODJFS oversight and independent control assurance.
Editorial currency note: This article reflects court, audit and inspector-general records available as of September 4, 2026. The Creel cases remain active following their guilty pleas, and additional plea, sentencing or account-access records could resolve some of the remaining questions.



