
Amazon Web Services declared its Bahrain cloud region and one UAE availability zone, mec1-az2, unrecoverable on September 15, 2026 after Iranian missile and drone strikes in March and April. Data stored exclusively in those footprints cannot be restored. The announcement moves a regional outage into a permanent data-loss event.
AWS is still working to restore services in the other two UAE zones and expects a Bahrain update in early 2027. The failure raises hard questions about the physical security of Gulf cloud infrastructure.
The cloud’s core promise is that no single building failure can erase your data. In Bahrain, a coordinated strike across multiple buildings erased an entire region. That promise is now broken.
The damage began in March after Iranian missile and drone strikes on Gulf states hosting U.S. military bases. Customers who had not migrated before the second strike now face a question no backup plan fully answers.
After repeated recovery attempts, the company stopped trying. What was a regional outage is now a permanent data-loss event. For companies that treated the Gulf as a bridge into Middle Eastern markets, the calculation has changed.
The question now is whether the Gulf remains a primary home for critical data or becomes a failover target. That answer will shape cloud investment far beyond the Gulf.
Redundancy failed where it was supposed to hold
The Bahrain region, me-south-1, took its first hit on March 1. The strike damaged multiple availability zones at once, something the architecture was never designed to absorb.
A second disruption followed in April. By then, AWS had already begun telling customers to move workloads elsewhere. Most did. Those who did not now face a harder reality.
What died in Bahrain was not just hardware; it was the assumption that redundancy equals survival.
By the time AWS made its announcement, the region’s infrastructure and data were beyond restoration. In the UAE, one availability zone will not come back, while work continues in the other two affected zones. AWS said it has exhausted every option for restoring data that was not migrated before the region became unavailable.
Rachel Cherniss, a research scientist at Georgia Tech’s School of Cybersecurity and Privacy, studies what happens when physical war reaches commercial cloud infrastructure. “Data centers are key forms of infrastructure that ensure AI can run,” she said. Researchers have noted that Iran’s strikes on commercial data centers represent the first deliberate wartime attacks on such infrastructure, raising questions about whether data centers will increasingly become military targets as AI becomes central to economic and military operations.
According to Reuters, citing a person familiar with the situation, some banking operations were disrupted. No bank or regulator has confirmed the scale.
The failure sequence below shows why the design assumption broke.
The design assumed fires, not missiles
The deeper failure is architectural. AWS regions are split into availability zones, each with separate power and cooling, so a fire or equipment fault stays local. Replication across zones preserves data when one zone drops. That model assumes the other zones remain standing.
In Bahrain, they did not.
That assumption sat underneath a regional build-out racing ahead of threat models. The UAE has become a magnet for hyperscale investment, and AWS now competes with Microsoft, Google, G42 and Khazna for sovereign AI workloads. Physical security was rarely the differentiator; Iran’s strikes made it one, and the market is now pricing it into every deal.
The capacity planned for the Gulf is already shifting. Analysts have noted that concerns over physical security from regional conflict are prompting some investors to consider alternative locations for data-centre capacity outside the Gulf region. That migration is a leading indicator of where the next data centres will be built.
The next update will not restore the data.
AWS has promised a Bahrain update in early 2027. It will show whether the Gulf remains a primary home for critical data or becomes a failover target.
Beyond the headline
The bigger picture
Cloud infrastructure is no longer an abstract digital layer. It is a physical asset vulnerable to the same kinetic threats as pipelines or power plants. Gulf governments built diversification agendas on data centres; Iran’s strikes showed concentrated compute can be disrupted at scale.
The reach
European financial regulators are watching. Supervised banks that rely on Gulf cloud regions must now reassess concentration risk, exit plans and data residency assumptions. The likely result is tougher scrutiny of cloud outsourcing and possible capital add-ons for firms whose contingency plans do not cover loss of an entire region.
The timing
The incident lands as the UAE accelerates its Stargate AI campus and Microsoft’s multi-billion-dollar build-out. Decisions taken in the next year on dispersing sites, hardening facilities and codifying resilience requirements will lock in risk profiles for a decade. The war damage forces those choices under immediate pressure.
The Gulf cloud calculus changes
With one AWS region unrecoverable and a UAE zone lost, companies with Gulf workloads face immediate decisions.
- Western company with AWS cloud operations in the Gulf
Check your exposure to me-south-1 and mec1-az2 now. Pull deployment inventories, confirm which backups exist outside those zones, and activate disaster recovery plans. Treat data stored only in those footprints as lost unless a verified replica exists elsewhere.
- Investor in Gulf cloud and AI infrastructure projects
Re-run risk models for Gulf data-centre assets. Hardened construction, site dispersion and power-grid redundancy now change project costs and timelines. Ask developers for updated physical-security designs before committing new capital.
- Compliance officer for Western firms operating in the Gulf
Review breach-notification duties under the UAE PDPL and Bahrain’s PDPL. If personal data was lost and your organisation is deemed a processor or controller under local law, the 72-hour notification window may already be running. Update data-processing agreements to cover emergency migration and cross-border transfers.
- Global supply chain manager for digital services
Map every service that depended on Gulf regions. Move critical workloads to multi-region or multi-cloud architectures, and test failover to Europe or North America before the next disruption. A single-region dependency is now a supply-chain risk.
FAQ
What recourse do AWS customers have for data that cannot be recovered?
AWS standard agreements generally limit liability for data loss and require customers to maintain their own backups. The company may offer billing relief or migration support, but consequential business losses are unlikely to be compensated. Regulated entities must also notify relevant authorities under local data-protection and sector rules when personal or critical data is affected.
Does moving workloads out of the Gulf trigger cross-border data transfer rules?
Yes. Shifting workloads to Europe or North America turns originally domestic data into cross-border transfers. Bahrain’s PDPL, the UAE’s PDPL and EU GDPR require lawful bases, adequate safeguards and sometimes prior assessment of destination protections. Data-processing agreements with AWS and other providers should explicitly cover emergency migration, encryption and access controls.
How can companies reduce exposure to a single Gulf cloud region?
Architect workloads across multiple AWS regions or adopt multi-cloud strategies combining AWS with Microsoft Azure, Google Cloud or regional providers. Replicate critical databases, decouple applications from region-specific services, and regularly test failover. Financial institutions may need board-approved cloud-resilience plans aligned with supervisory expectations on operational resilience and third-party risk.
Explainer
- Availability zone
- A distinct cluster of data centres within an AWS region, engineered with separate power, cooling and network paths. The isolation is meant to contain failures such as fires or equipment faults. In Bahrain, multiple zones were hit at once, defeating the isolation model.
- me-south-1
- The AWS region code for Bahrain. It is part of AWS’s Middle East footprint and was the first Gulf region declared unrecoverable after physical attack. The code appears in AWS health-dashboard notices and customer migration guidance.
- PDPL
- Personal Data Protection Law, the name used for both the UAE’s Federal Decree-Law No. 45 of 2021 and Bahrain’s data-protection statute. Both impose breach-notification and data-protection duties on controllers and processors, including foreign cloud providers. Neither law has been tested for cross-border liability when war destroys a commercial cloud region.
- G42
- An Abu Dhabi-based AI and cloud computing company. It is a central player in the UAE’s sovereign AI ambitions, including the Stargate campus. G42 competes with AWS and Microsoft for Gulf AI infrastructure deals.





