Other use cases

Top 5 use cases for unstructured data intelligence with graph analytics

September 16, 2026
12 minutes

Complex investigations can take many forms: tracing a sophisticated insurance fraud ring, mapping an international money laundering network spanning real estate and shell companies, or reconstructing digital evidence from terabytes of data. But they often run into the same wall: harnessing vast amounts of unstructured data and revealing critical connections hidden within the evidence. 

Traditional systems can readily process structured data. But valuable clues can also be buried in emails, case notes, witness statements, documents and other unstructured content. Extract and connect those details, and they can reveal relationships that would otherwise remain hidden.

Unstructured data intelligence is what makes that extraction possible. Point it at a stack of documents, chat logs, or case notes, and it reads through all of it, pulling out the information buried inside. Extracting those details used to require someone reading every page by hand, but with unstructured data intelligence, free text turns into something an investigator can actually query.

Graph technology takes the next step: revealing how all that information connects. Every person, account, or other entity becomes a node. Every relationship between them becomes an edge linking two nodes together. Instead of examining each piece of evidence in isolation,  investigators visually explore the wider network at once, and a connection that would have taken hours to trace across a stack of spreadsheets shows up in a single glance.

This article explores five areas where that combination can change how investigations are conducted: forensic data analytics, fraud investigations, law enforcement, anti-money laundering, and investigative journalism. Across each, the principle is the same: unlock more of the information hidden in complex data, connect the dots, and give investigators a clearer picture of what they’re looking at.

Forensic data analytics 

Forensic data analytics, the branch of digital forensics focused on finding patterns of criminal activity, only works once investigators have tracked down the sources that might hold relevant evidence, and that alone can be the hardest part of the process. It only gets harder as a case spans more borders, generates more data, and pulls in more formats that don't talk to each other. Typical sources include:

  • Laptops and mobile phones
  • Servers and cloud accounts
  • Transaction logs
  • Chat platforms and communication records

Even once every source is tracked down, investigators still need to make sense of what is often a fragmented mix of structured and unstructured data and the connections between them aren't spelled out anywhere.  A name mentioned in a chat, a date in a document, or an account number stored in a transaction record may all relate to the same person or event, with nothing to show they're the same thread.

What it looks like in practice 

A suspect under investigation for embezzlement has a seized laptop with a deleted text file, a draft note referencing a vendor name. Their phone extraction has a chat message: 'the Acme Inc. invoice is handled, keep it between us.' A separate email thread includes an invoice from that same vendor, approved and forwarded by the suspect.

None of these sit in a structured field an investigator would think to query together. They're scattered across a recovered file, a chat log, and an email attachment, all within the same case. Mapped as connected entities instead of three separate evidence folders, the vendor name becomes the thread tying the deleted file, the chat message, and the invoice into one pattern the investigator could review directly.

How unstructured data intelligence with graph visualization can help 

Closing that gap is what an unstructured data intelligence platform with graph analytics and visualization is built to do. Entity matching indicates that the vendor name in the deleted spreadsheet, the chat message, and the invoice all refer to the same entity, rather than three coincidental mentions. 

Graph analytics and visualization then maps those matched entities as a connected structure, surfacing links that would otherwise take hours of manual cross-referencing to find.

Together, these capabilities turn fragmented evidence into a connected view of the people, events, relationships, and information relevant to the investigation.

Fraud investigations 

Organized fraud rings have a playbook, and step one is looking unremarkable. Each claim clears review on its own, with nothing to connect it to any other. The connections between those claims may be hiding in places traditional fraud controls struggle to exploit: claim narratives, email threads and notes. Combined with the structured information already available, those clues can reveal a very different picture.

What it looks like in practice 

At an insurance company, an adjuster reviewing a single claim has no way to know it's one of three. They see an amount, a policy number, a date of loss, all within normal range. What they can't see is that a repair shop is quietly inflating damage estimates across multiple claims, working with claimants recruited specifically to file them. 

That shop's name shows up in another adjuster's free-text notes on a different claim, and again in a voicemail transcript attached to a third. None of the three claimants know each other, and none of the three adjusters have any reason to compare notes. Each detail sits in a different claim, a different format, reviewed by a different person, with no shared field connecting any of it.

How unstructured data intelligence with graph visualization can help 

Unstructured data intelligence processes the notes, images, and attachments across all three claims and pulls those details out as identifiable entities: a shop name, a phone number, a location, each one now something a system can actually match against the others.

Graph analytics and visualization is what makes the result visible and explorable: it connects people, businesses, and claims instead of examining them one at a time. An analyst pulling up the repair shop's node sees every claim linked to it in one view, filed by different adjusters, different dates, different claimants, instead of having to already suspect a connection before going looking for one. What used to depend on memory now shows up automatically, the moment three claims share a single detail buried in unstructured text.

Anti-money laundering investigations 

AML risk doesn't always show up where automated screening looks for it, and two separate problems make it hard to catch. First, the evidence needed to uncover it is often scattered across different sources, corporate filings, ownership disclosures, adverse media, internal records, much of it buried in unstructured text rather than sitting in a structured field. 

Second, the relationship that matters is often several steps removed, layered through intermediaries and ownership structures rather than sitting in a single and direct link. Look at each source and each entity in isolation, and the risk stays invisible; follow the money and the connections, and a different picture can emerge.

What it looks like in practice 

A transaction monitoring alert flags a wire transfer as unusual. The analyst investigating it requests supporting documentation, and the client provides an invoice justifying the payment: a supplier billing for their services. Nothing in the documentation or the wider account activity immediately contradicts the client’s explanation, so the alert is closed.

Weeks later, a different alert fires on a completely unrelated client's account. Same process: the analyst requests documentation, the client provides an invoice from a different, unrelated supplier, the transaction appears consistent with the explanation provided, so the alert is closed as well.

Neither analyst has any reason to compare the two invoices, but the phone number and address on both, supposedly two separate suppliers, are identical. A phone number and address showing up as the contact detail behind two supposedly separate businesses is exactly the kind of overlap that can point to connection between the businesses, potentially indicating a shell-company structure or a wider network being used to support suspicious transactions.

How unstructured data intelligence with graph visualization can help 

In AML investigations, unstructured data intelligence can extract names, organizations, addresses, account numbers, phone numbers, and other relevant details from supporting documents, case notes, and other free-text sources. This makes information that would otherwise remain buried available for analysis alongside structured transaction and customer data.

Graph analytics and visualization is what makes that overlap visible and explorable. In this example, an analyst could see that both closed alerts, filed weeks apart on unrelated accounts, are backed by invoices sharing the same phone number and address. That shared contact detail becomes a lead worth reopening and exploring further.

Instead of investigating each alert or customer in isolation, analysts can follow connections across cases and data sources to uncover wider networks of potentially suspicious activity that may not be visible from any single transaction alone.

Law enforcement investigations 

Criminal investigations generate evidence across different teams and formats: reports, interview notes, surveillance data, open source intelligence. As investigations grow, the challenge isn’t just finding relevant information. It’s understanding how people, places, events, and pieces of evidence relate across an increasingly complex body of data. Without a shared, connected view, investigators can spend valuable time piecing together context that already exists somewhere across their evidence.

What it looks like in practice 

A detective working a fraud case seizes a suspect's phone. Buried in a chat conversation, the suspect mentions sending payment to a wallet address, just typed into the message.

A separate, unrelated case, a different detective, a different suspect, includes a document where that same wallet address appears again, this time in a screenshot of a transaction the second suspect forwarded to someone else.

Neither case treats the wallet address as significant on its own, it's a string of characters buried in a chat message in one file and inside an image in another. Nothing about how these two cases were opened or investigated would necessarily reveal that they share the same wallet address.

How unstructured data intelligence with graph visualization can help 

Unstructured data intelligence technology processes the evidence and extracts relevant details from sources such as emails, reports, messages, transcripts and attachments, while also making available metadata and other structured or semi-structured information such as dates, timestamps, and geolocation information.

Graph analytics and visualization bring those details together in context. An analyst working either case can connect the wallet address mentioned in one case's chat log with the wallet address in another case's forwarded transaction, revealing that two otherwise separate suspects were dealing with the same wallet.

That shared wallet becomes a new lead to explore. Investigators can then expand the network around the people, locations, events, and evidence involved to see what else the two cases may have in common.

Journalism and NGO Investigations 

A leaked document dump can contain millions of files and reference a vast number of entities  across scanned contracts, incorporation records, registration forms, and correspondence spread across multiple languages and formats. No single document tells the full story on its own. The real ownership or control behind an entity is rarely stated outright, it's built up in pieces, a name on one filing, an address on another, a director listed in a different jurisdiction years later. 

The connection only emerges when those fragments can be analyzed together across documents and at a scale that is extremely difficult for investigative journalists to handle manually. Finding that connection means tracing a chain across documents that were never meant to be read together, filed in different jurisdictions, years apart, by people who had every reason to keep them looking unrelated.

What it looks like in practice 

Two hundred thousand documents in a leak doesn't mean two hundred thousand stories. It may mean one story broken into pieces and scattered, with no way to know which pieces belong together.

Investigators faced exactly this problem across the Panama Papers. Mossack Fonseca built more than 214,000 shell companies. Across the firm's business, using a nominee director, a placeholder name standing in for the real owner, was standard practice.

At that volume, across 11.5 million files, 2.6 terabytes of data and 30 years worth of crime, no team of journalists could check for that kind of overlap by reading documents one at a time. The connections were there, but nobody could see it.

How unstructured data intelligence with graph visualization can help 

Unstructured data intelligence helps turn large and heterogeneous document collections into something investigative journalists can actually work with. It can process scanned filings, agreements, correspondence, and other records at scale, extracting names, organizations, addresses, dates, signatories, and other relevant details that would otherwise remain buried across thousands or millions of files.

Graph visualization and analytics add the relational layer. Investigators can visually explore how companies, directors, addresses, intermediaries, funding sources, and public figures connect, while graph analysis helps identify patterns within those networks, such as recurring intermediaries, clusters of related entities, indirect connections, or chains linking one organization to another.

That changes both the scale and depth of the investigation. Investigators can follow ownership and control structures, test hypotheses, identify promising leads, and move through complex networks without losing sight of the underlying evidence. Patterns that would be extremely difficult to reconstruct manually become easier to identify, explore, and verify.

This is exactly what played out with the Panama Papers. Nuix's tools made millions of spreadsheets, documents, emails, and other unstructured data available for analysis across multiple languages and formats, while removing duplicates and irrelevant data. ICIJ's data team transformed the leaked files into a connected graph structure and used Linkurious to visualize it. That enabled more than 370 journalists in over 100 newsrooms to analyze the entire network at once, surfacing context and connections that reading files one at a time might never have caught.

Turning buried data into a connected graph 

Across all five use cases, the challenge is fundamentally the same: valuable information is often buried in unstructured data, while the relationships that give that information meaning are scattered across a much wider body of evidence. Investigators need to do both: bring more of that information into the investigation and understand how it connects.

Nuix with Linkurious closes that gap, addressing those two sides of the problem within Nuix Neo. Nuix Neo processes over 1,000 file types at terabyte scale, extracting relevant information from emails, documents, chats, scanned records, and other sources and making it available for analysis alongside existing structured data. Then, it can automatically turn those entities and relationships into an interactive network that investigators can explore directly.

Instead of reviewing individual records or documents in isolation, they can follow connections, identify patterns, expand around new leads, and understand the wider context surrounding an investigation.

With unstructured data estimated to account for up to 90% of enterprise information, a significant share of potentially relevant context can otherwise remain difficult to access and analyze. The opportunity is not simply to process more data, but to bring more of the available evidence into complex investigations and turn it into context investigators can actually use.

Get in touch with us 

Every use case above starts with the same question: what's hiding in the unstructured data you already have? Get in contact with our experts to talk through what that could look like for your team.

FAQ

What's the difference between structured and unstructured data?

Toggle

How does graph analytics work with unstructured data?

Toggle
Subscribe to our newsletter

A spotlight on graph technology directly in your inbox.

TOP