- AWS said two facilities in the United Arab Emirates were directly struck by Iranian drones; a Bahrain facility was physically affected by a drone strike nearby. It did not identify the sites.
- Two of the UAE region's three availability zones were impaired at the same time. That correlated failure produced severe disruption even though a third zone remained normal.
- The wider risk extends from data-centre geography to cable repair and power, but the reviewed record does not show a subsea cable cut in this conflict or prove that every company on an attributed Iranian target list was attacked.
The cloud entered the conflict as a physical asset
A cloud region sounds abstract until concrete, power and cooling fail. In its service history, Amazon Web Services said two facilities in the United Arab Emirates were directly struck by Iranian drones. In Bahrain, AWS recorded physical impact from a drone strike in close proximity. The company described structural damage, power disruption and damage associated with fire suppression and water. It did not disclose the exact facilities, so public reporting cannot safely map those statements to named campuses.
The distinction between direct and nearby impact matters. So does the distinction between an AWS facility and every digital service that later malfunctioned. ABC reported serious effects on banking, taxi and food-delivery services, while AP independently described damage to three AWS facilities as a warning about regional data-centre vulnerability. Those reports establish a broad civilian dependency problem; they do not establish that every outage had one identical technical cause.
Three availability zones did not remove correlated geography
AWS documents three availability zones in both its UAE and Bahrain regions. An availability zone is designed as a distinct failure domain, and customers can distribute workloads between zones. During the UAE incident, however, AWS reported simultaneous impairment in two zones while the third operated normally. Redundancy existed, but the event crossed more than one local boundary at once.
This does not make multi-zone architecture useless. It changes the question. A design that survives a server, building or single-zone failure may still depend on shared regional power, telecommunications, staff access, repair capacity and a small geographic footprint. Customers also determine whether applications actually replicate, fail over and recover across zones or regions. Provider architecture and customer architecture therefore share the outcome.
AI demand deepens the coupling between computation and security
ABC's central observation was not simply that artificial intelligence can assist military analysis or targeting. It was that the computation behind those uses occupies facilities that also support banks, logistics platforms and ordinary communications. Once compute is treated as strategic capacity, the same site can carry military relevance in one narrative and civilian consequence in another.
The Gulf is simultaneously planning much more capacity. OpenAI describes Stargate UAE as a planned one-gigawatt cluster in Abu Dhabi, with an initial 200 megawatts expected to come online in 2026. Those figures are a plan and an expectation, not current deployed capacity, and the reviewed sources do not identify Stargate UAE as an attacked site. The project is relevant because it would concentrate more high-value compute, energy demand and international partnerships in the same regional operating environment.
A target list is not an attack ledger
ABC, citing Al Jazeera, reported that Iran's Islamic Revolutionary Guard Corps had published a list of possible new targets that included data centres or offices associated with several US technology companies. That is an attributed targeting claim. It does not prove that every named company, office or data centre was struck, used for military operations or suffered an outage.
Careful assessment has to keep four states separate: a party's stated rationale, a target named on a list, a verified physical impact and an observed service failure. Collapsing them turns wartime messaging into false precision. AWS's own service history is the strongest source for the damage it acknowledged; claims about intent and other companies remain bounded by their attribution.
Cable exposure is a repair and concentration problem, not a reported cut
TeleGeography estimates that more than 90% of Europe–Asia capacity passes through Red Sea routes. It separately identifies active systems crossing the Strait of Hormuz and notes that repair vessels depend on permits and safe access. These are durable concentration and repair risks. The Red Sea and Hormuz are also different corridors: disruption in one cannot automatically be described as a cut in the other.
No reviewed source documents a submarine-cable cut caused by this Iran conflict. The useful watchpoints are landing-station access, power continuity, vessel permits, repair backlogs and route diversity. Cable redundancy, like cloud redundancy, must be tested against correlated geography rather than counted as a number of nominal paths.
The resilience test moves beyond a single region
Operators should now disclose which failure domains are genuinely independent, how long applications can run through a two-zone impairment, and which services can fail over to another region without losing data, identity controls or regulatory compliance. Boards need recovery-time evidence from exercises, not a diagram that stops at three zone icons.
The episode does not show that cloud concentration is avoidable or that every workload should leave the Gulf. It shows that logical redundancy is only as strong as the physical and operational systems beneath it. The next proof will be measured in restoration time, cross-region recovery, transparent incident boundaries and whether planned expansion reduces or compounds geographic concentration.

