For most businesses the cloud is an abstraction, a place with no location. The war between the United States and Iran has shown that it is not. For months now, Amazon’s cloud region in Bahrain has been effectively offline, and a second region in the United Arab Emirates has been running at reduced capacity, both because their facilities were physically damaged. For any business that put its data in one place and assumed the provider would keep it running, this is the scenario the sales brochure never mentions.

A Region That Has Been Dark Since Spring

Amazon divides the world into “regions”, each a cluster of data centers in one country. Bahrain, opened in 2019 as Amazon’s first cloud region in the Middle East, is one of them. The damage came in a series of blows:

  • Early March: over a weekend, drones struck two Amazon facilities in the UAE, and a strike close to a Bahrain facility damaged its infrastructure. In the UAE, two of the region’s three data-center zones went offline, with a fire that set off sprinklers and damaged equipment.
  • Late March: the Bahrain region was disrupted a second time by drone activity.
  • April 1: a fire broke out at what was reportedly an Amazon data center in Bahrain, a blaze the country’s government attributed to the Iranian attacks.

No casualties were reported at the Amazon facilities. The business disruption, though, was immediate, reaching from banks and payment services to the ride-hailing app Careem.

Months later, little has changed. Amazon’s own status page still lists Bahrain as “currently unavailable” and the UAE as unable to reliably support customer applications, with the last update dated April 30. Amazon’s guidance has shifted from repairing in place to asking customers to move their systems to other regions, and it says many already have. It waived its UAE charges for March. This is not a normal outage. Ordinary cloud failures last hours and are fixed remotely. This one is measured in months, because the repair means fixing damaged facilities, power and cooling, not rolling back software.

Why Losing One Region Should Not Break You, and Why It Did

Amazon designs each region with separate zones precisely so that one failure does not take everything down. A zone is an independent data center with its own power and cooling, so if one burns, the others are meant to carry the load. That model is built for accidents like storms and power cuts. It is not built for a strike that knocks out multiple zones at once, which is what happened in the UAE.

There is a second, less comfortable point buried in Amazon’s own rules. Under what it calls the shared responsibility model, Amazon keeps the infrastructure running, but spreading your systems across more than one region is the customer’s job, not Amazon’s. Companies that treated multiple zones inside a single region as enough protection found they had none when an entire region went dark, as happened in Bahrain.

The Claim AWS Never Confirmed

On July 21, Iran’s Revolutionary Guard said that a day earlier it had struck Amazon’s Bahrain infrastructure with cruise missiles and destroyed it, describing the attack as retaliation for what it said was an American strike on an Iranian nuclear site. It is worth being careful here. No independent party has confirmed the July strike. Bahrain said its air defenses had intercepted Iranian missiles and drones that day, but said nothing about Amazon. Amazon declined to comment, and its status page had not moved since April. The region had already been offline for months, which makes a fresh claim of destruction difficult to verify independently. The episode is a lesson in wartime information as much as in infrastructure. A combatant has an obvious incentive to announce a spectacular strike, and a facility that is already offline gives the outside world very little to check such a claim against.

From a Fire in Strasbourg to a Strike in the Gulf

This is not the first time a single site has failed and taken unprepared customers with it. In March 2021, a fire destroyed an OVHcloud data center in Strasbourg and knocked around 3.6 million websites offline, and some customers discovered they had no backup outside the building that burned. In October 2025, a single Amazon region in the United States failed for the better part of a day because of a software fault, and outage trackers counted more than a thousand companies disrupted. Each event pushed the same lesson one step further. Relying on one data center is fragile, relying on one zone is fragile, and now, relying on one region can be fragile too.

When the Insurance Says “Act of War”

There is a financial sting that makes this worse than an ordinary outage. Standard business insurance policies frequently exclude acts of war, and Iran publicly claimed the strikes as exactly that. Legal analysis published since the strikes points out that force majeure clauses, which normally excuse a company from its obligations during events beyond its control, may not protect a provider operating in an active conflict zone, where disruption is arguably foreseeable. In plain terms, a company knocked offline by a strike may find that neither its provider nor its insurer is obliged to make it whole.

What to Do If Your Business Runs in One Region

The lesson is not to abandon cloud hosting, which stays reliable in the overwhelming majority of cases. It is to treat the location of your data as a decision with real stakes. Know which region your systems actually run in. Keep backups somewhere geographically distant. If your business cannot survive a region being gone for months, arrange for it to run from a second region, or a second provider, and test that it works before you need it. And when you choose a region, weigh not only its price and speed but the stability of the place it physically sits in. The cloud has an address. In 2026 that stopped being a technicality.