All Articles
AWS Data Centers Hit by Iranian Drone Attacks: Cloud Risks Investors Must Now Watch
Markets5 min read

AWS Data Centers Hit by Iranian Drone Attacks: Cloud Risks Investors Must Now Watch

By Redaktion aktie.com · Reviewed by Martin Schülbe

This article was created with the help of artificial intelligence.

Key Takeaways

  • On March 1, 2026, Iranian drones struck three AWS data centers in the United Arab Emirates and Bahrain—the first confirmed military attack on the infrastructure of a hyperscale cloud provider.
  • Two availability zones in the AWS region ME-CENTRAL-1 (UAE) and one zone in the region ME-SOUTH-1 (Bahrain) failed simultaneously, causing standard redundancy systems to fail, which are designed only for individual zone failures.
  • In September 2026, AWS acknowledged permanent data loss: access to data that existed only in the availability zone mec1-az2 (UAE) or in the Bahrain region cannot be restored.
  • Affected companies included Abu Dhabi Commercial Bank, Emirates NBD, First Abu Dhabi Bank, the payment platforms Hubpay and Alaan, as well as Snowflake and Careem.
  • Ashish Nadkarni of IDC explained on March 20, 2026, that the protection of data centers is now comparable to the protection of government buildings with the highest security level.
  • Google, Microsoft, and Oracle also operate data centers in the region and are thus positioned in an active conflict zone, creating concentrated geopolitical risk for investors.

On March 1, 2026, Iranian drones struck three Amazon Web Services (AWS) data centers in the United Arab Emirates and Bahrain. The Islamic Revolutionary Guards Corps (IRGC) officially took responsibility for the attacks, justifying them with the role of the data centers in supporting U.S. military and intelligence networks. This was the first publicly confirmed military attack on the infrastructure of a hyperscale cloud provider.

Two availability zones in the UAE went down simultaneously

The drone attacks struck two availability zones in the AWS region ME-CENTRAL-1 (UAE) and one zone in the region ME-SOUTH-1 (Bahrain). AWS confirmed on March 5, 2026, structural damage to the facilities, power outages, fire damage, and water damage from activated fire suppression systems. The simultaneous failure of multiple zones proved critical: standard redundancy models from cloud providers are designed for the failure of individual zones—the simultaneous failure of two zones in one region and another in Bahrain overwhelmed the failover systems.

By late April 2026, more than a month after the attacks, AWS service dashboards still showed the status "disrupted" for affected services in the regions. AWS warned of prolonged recovery times. In September 2026, the company finally acknowledged permanent data loss: access to resources and data that existed only in the availability zone mec1-az2 (UAE) or in the Bahrain region cannot be restored. The destroyed infrastructure is to be replaced; AWS indicated that further information would be provided in early 2027.

Financial services companies and international enterprises affected

Affected companies included Abu Dhabi Commercial Bank, Emirates NBD, First Abu Dhabi Bank, and the payment platforms Hubpay and Alaan. The data cloud company Snowflake and the mobility platform Careem also experienced outages. Many affected companies had no deliberate presence in the Middle East—their cloud workloads were automatically routed through the region, which they were unaware of until the disruptions occurred.

Iranian state media described the AWS facilities as legitimate targets because the U.S. military uses AI systems on AWS—specifically naming Anthropic's Claude for intelligence analysis and war simulations. Iran claimed to have also attacked Microsoft facilities; Microsoft officially denied this and reported neither hits nor outages.

Geopolitical risk cannot be designed away

Sam Winter-Levy, fellow at the Carnegie Endowment, explained on March 20, 2026, that such physical attacks would become more frequent as the importance of AI infrastructure grows. Winter-Levy had already warned in July 2025 in an opinion piece in the Washington Post against building critical computing infrastructure in the Gulf region, pointing to growing tensions between the United States and Iran.

Analysts point out that data centers become attractive targets in asymmetric conflicts as the economy's dependence on cloud services increases. The attacks on March 1, 2026, demonstrated that cloud providers cannot technically eliminate geopolitical risks through redundancy and failover systems alone.

Industry calls for military-grade protection for data centers

After the attacks, the tech industry raised the question of whether data centers should be defended like military installations. Ashish Nadkarni, who leads global infrastructure research at IDC, explained on March 20, 2026, that the protection of data centers is now comparable to the protection of government buildings with the highest security level.

IDC reported that damage to AWS infrastructure would lead to increased investment in data infrastructure, as companies wanted to diversify their data storage. In the Middle East, cloud providers are increasingly relying on "multi-AZ" deployments—data copies are stored in separate data centers. Globally, companies and governments expect data center operators to provide recovery plans and multiple sites within a country.

Underground bunkers as a new security strategy

Data storage providers began establishing underground facilities worldwide in former Cold War atomic bunkers, caves, and mountains to attract security-conscious customers. Facilities in the United Kingdom are described as capable of withstanding nuclear explosions.

Gulf states have committed hundreds of billions in investment to AI data infrastructure. To attract customers, these governments must now offer enhanced security measures. The March 1, 2026, attacks create competitive pressure for regional data center operators to differentiate themselves through enhanced physical security.

What investors should watch in cloud stocks

The incidents raise new questions for investors. Cloud infrastructure was considered geographically diversified and thus resilient—the simultaneous failures of multiple availability zones show the limits of this assumption. Google, Microsoft, and Oracle also operate data centers in the region and are thus positioned in an active conflict zone, creating concentrated risk.

The attacks represent an unprecedented scenario: the targeted military attack on commercial cloud infrastructure as a war objective. There are hardly any developed legal precedents or frameworks governing military attacks on civilian infrastructure for this scenario.

For investors in cloud and tech stocks, this means: geopolitical risks must be weighted more heavily when evaluating hyperscale cloud providers. Companies with diversified geographic infrastructure, clear recovery plans, and investments in physical security are likely to be better equipped for such scenarios. The question of whether war damage to data centers is insurable and how liability risks are split between cloud providers and customers remains unresolved.

Sources

Share Article

X LinkedIn
Comments (0)

Sign in to comment.

You might also be interested in

Subscribe to newsletter

Get the most important market updates and analyses delivered to your inbox every week.