AWS has confirmed it cannot restore access to resources and data in one availability zone of its Middle East (UAE) region and across its entire Bahrain region, following conflict-related strikes in the Middle East. For UK infrastructure buyers, the episode is a live case study in why a named secondary region on paper is not the same as a tested, working failover.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| Initial strikes (Mar 2026) | 0 | 8 |
| Second Bahrain strike claimed | 18 | 4 |
| AWS confirms permanent loss | 24 | 2 |
| Bahrain rebuild update due | 44 | 8 |
What AWS has actually confirmed
AWS says it is unable to restore access to resources and data held exclusively in the mec1-az2 availability zone of its Middle East (UAE) region, me-central-1, and continues working on the region's other two zones, mec1-az1 and mec1-az3.
For its Bahrain region, me-south-1, the position is starker: AWS says damage spanned multiple availability zones and exceeded what its regional and multi-AZ services are designed to withstand, and it cannot restore access to resources and data hosted exclusively in that region. AWS has said it will share further plans for Bahrain in early 2027.
AWS and later reporting linked the damage to conflict-related strikes beginning in March 2026, with additional reporting in July referring to a second Bahrain attack claim. Bahrain opened in 2019; the UAE region followed in 2022.
The availability zone assumption just failed a real-world test
Cloud architecture guidance has long told buyers that spreading workloads across multiple availability zones within a region protects against localised failure — a fire, a power fault, a flooded plant room. That assumption held for accidental faults. It did not hold for coordinated physical attacks that crossed AZ boundaries and, in Bahrain's case, took out the entire region's design margin at once.
That distinction matters for any UK organisation whose DR plan assumes 'multi-AZ' equals 'safe.' Multi-AZ protects against uncorrelated failure. It was never designed, and AWS itself now says it was not built, to survive a scenario where every zone in a region is damaged in the same event.
Multi-region failover: nominal versus tested
AWS's own advice to affected customers was to migrate accessible resources to other regions and restore inaccessible ones from remote backups, naming Europe, the US and Asia Pacific as fallback options. Vendors including Red Hat and Snowflake issued similar guidance, urging customers to actually invoke their disaster recovery plans rather than simply reference them.
The gap this exposes is a familiar one for anyone who has read why RTOs are often a lie without testing: a documented secondary region is not the same as a proven one. If your failover has never been exercised against a scenario where the primary region is gone for months, not minutes, the recovery time objective on paper is a guess. UK buyers should understand disaster recovery testing types well enough to know which one — tabletop, partial, or full failover — actually validates a region-loss scenario rather than just a single-service outage.

Data residency risk when a region simply stops existing
For firms that chose Bahrain or UAE specifically for data residency, sovereignty, or latency reasons tied to Gulf operations, this event removes a variable many contracts assumed was fixed: the region itself. Data described by AWS as hosted exclusively in the affected zones is not coming back, which reframes region selection as a genuine business continuity decision, not just a compliance checkbox.
UK organisations with Gulf subsidiaries, Middle East customer data obligations, or contractual commitments referencing specific AWS regions should revisit those agreements now, before a similar disruption forces the conversation under pressure.
What this means for UK DR and procurement decisions
This is being described as the first confirmed military attack on a hyperscale cloud provider, and it has sharpened scrutiny of cloud-region risk assumptions well beyond the Gulf. UK buyers with any exposure to conflict-adjacent regions, or who simply want to stress-test their own resilience planning, can track major cloud outages to see how frequently 'temporary' regional disruption becomes permanent.
Practical priorities now include validating that backups are genuinely remote rather than merely in a different AZ of the same region, re-testing failover runbooks against a total region-loss scenario rather than a single service degradation, and reviewing SaaS platforms — including Microsoft 365 — against the same standard via a proper Microsoft 365 backup comparison.
- •Confirm remote backups sit in a genuinely separate region, not just a separate AZ
- •Re-test failover runbooks against total region loss, not partial degradation
- •Review contracts referencing specific regions for residency and continuity clauses
- •Quantify exposure with a downtime cost calculator before, not after, an incident
Building resilience that survives a worst case
The organisations best placed through this disruption were those who had already treated AWS's nominal region redundancy as a starting point rather than an endpoint, layering independent backup and recovery tooling on top. For teams weighing that investment, it is worth working through options to explore backup and disaster recovery solutions, including platforms such as Veeam that support recovery into alternate regions or providers when a primary environment is unavailable for months rather than hours.
- 01DataCenterDynamics — AWS 'unable to restore access' to data centers hit by Iran strikes · 16 September 2026
- 02The Register — Iran says it struck offline AWS facility in Bahrain again · 21 July 2026
- 03The Register — Tech vendors urge failover from hit Middle East AWS regions · 4 March 2026
- 04Tom's Hardware — Amazon's Middle East data centers damaged, down for several months during repairs · 3 May 2026
- 05BleepingComputer — Amazon: Drone strikes damaged AWS data centers in Middle East · 3 March 2026
- 06Computer Weekly — Drone strikes show why key military principles apply to cloud data · 15 April 2026
- 07tomshardware.com
- 08tomshardware.com
