Per AWS’s Health Dashboard update, the company determined it cannot restore access to the resources and data hosted exclusively” in its Middle East (Bahrain) region. AWS also confirmed permanent loss for data held exclusively in one of its three UAE availability zones, specifically mec1-az2.
What AWS Said, and What It Means
The company’s own language acknowledged a failure that its redundancy architecture was never designed to survive.
The damage to our infrastructure spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand.
Amazon Web Services, AWS Health Dashboard status update, September 15, 2026
That sentence carries real weight. AWS, like every major cloud provider, builds each region with multiple independent data centers called availability zones. The design goal is straightforward: a failure in one location should not cascade into total loss.
When all of them sustain simultaneous physical destruction, the redundancy model breaks down completely. If your data lived exclusively in Bahrain or in mec1-az2 without cross-region replication, that data is gone.
The confirmed loss applies only to data stored exclusively in the Bahrain region or in mec1-az2. Customers who practiced cross-region replication or maintained remote backups were protected. According to Reuters, AWS confirmed that most affected customers had already migrated their workloads to other regions following guidance issued back in March.

How the Attacks Unfolded
The damage accumulated across weeks, compounding with each new strike.
On March 1, 2026, objects struck a UAE data center and triggered sparks and fire. The blaze was severe enough that firefighters cut power to the facility, according to Reuters.
AWS confirmed the next day that drone strikes had damaged facilities in both the UAE and Bahrain. Structural damage, power disruption, and fire-suppression water damage affected multiple sites.
The company warned customers that recovery would be “prolonged,” urged immediate migration of workloads to unaffected regions, and suspended billing in the impacted areas. That billing suspension was confirmed in the April 30 AWS update.
A second disruption hit the Bahrain region on March 24 following further drone activity, per Reuters reporting. By April 30, AWS acknowledged that recovery would take several months, with dozens of core services including EC2, S3, DynamoDB, Lambda, and RDS listed as disrupted.
Infrastructure reporting by Tom’s Hardware described the March strikes as the first confirmed military attack on a hyperscale cloud provider. Iran’s Islamic Revolutionary Guard Corps claimed it targeted the Bahrain site because of U.S. military workloads hosted there. AWS declined to comment on that claim.
What Comes Next, and What It Means for Your Architecture
The confirmation turns a theoretical risk into a documented precedent that your backup strategy can no longer ignore.
AWS said it is replacing affected infrastructure in the UAE and will issue a further restoration update in the coming months. For Bahrain, the company said a long-term update will follow in early 2027.
If your workloads currently live in a single region without cross-region replication or offline backups, this incident is the clearest argument you will find for changing that. A single-region deployment now carries the same logic as keeping your only copy of something irreplaceable in one physical location: reasonable until the moment it is not.
Regulators, insurers, and enterprise risk teams will now face pressure to treat physical conflict as a design requirement rather than a planning footnote. A scenario that once lived at the bottom of a threat model just moved to the top of the agenda for any cloud provider operating in contested regions.




























