Amazon Web Services cannot restore access to resources and data that remained exclusively in its Middle East (Bahrain) region. In an update posted to its status page on September 15, the company said that “after a thorough assessment, we have determined that we are unable to restore access to the resources and data hosted exclusively in this Region.” The damage, it said, “spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand.” A second update the same day said the same of one of the three zones in the nearby Middle East (UAE) region, mec1-az2, while work continues on the other two. AWS will give a further update on the UAE “in the coming months” and on Bahrain in early 2027.
The disruption began in the UAE on March 1, with Bahrain reporting its own localized power issue the following day. AWS first described each incident as affecting a single Availability Zone. In a later update it said that both regions had “experienced physical impacts to infrastructure as a result of drone strikes” connected to “the ongoing conflict in the Middle East,” with two facilities in the UAE struck directly and one in Bahrain damaged by a strike nearby. An April 30 notice listed the Bahrain region as unavailable. The September note explains that this followed disruption to a second Bahrain zone in April. The September update is the first public notice to state that access to some of what was left behind cannot be restored.
Key facts
- Bahrain, me-south-1: AWS cannot restore access to resources and data hosted exclusively in the region. According to the notice, most customers migrated before the region became unavailable in April, and the rest have since re-established elsewhere, “using backups where available.”
- UAE, me-central-1: AWS cannot restore access to resources and data hosted exclusively in zone mec1-az2. Regional resources, along with zonal resources hosted in the two other affected zones, mec1-az1 and mec1-az3, are still being recovered. Replacement of the affected infrastructure is under way, per the notice.
- What AWS asked for: from the first days of March, replication of S3 and critical data to another region. From April 30, migration of whatever remained accessible and recovery of the rest in other regions from remote backups. On April 30 AWS also said relevant billing operations for both regions were suspended.
- What the notices leave out: any number of affected customers or measure of the data involved. That “most” customers migrated in time is the only indication given, along with a note that the relevant authorities have been notified.
Designed to Withstand
AWS’s global infrastructure page describes how its regions are built. It says that each region “consists of a minimum of three, isolated, and physically separate” Availability Zones, each with independent power, cooling and physical security, and that the zones are “physically separated by a meaningful distance, many kilometers, from any other AZ, although all are within 100 km (60 miles) of each other.” Companies that spread an application across zones, the page says, are “better isolated and protected from issues such as power outages, lightning strikes, tornadoes, earthquakes, and more.” The September 15 note is AWS’s own statement that in Bahrain the damage went past that design: more than one zone in one geographic area.
The global infrastructure page is not a live service-status page, but as of September 17 it still counted 124 Availability Zones in 39 regions, a total that includes all three zones in Bahrain, listed as launched in 2019, and all three in the UAE, launched in 2022. For the UAE, the notice speaks of “working on replacing the affected infrastructure,” which reads as an intention to rebuild. For Bahrain it commits to supporting customers “in the long term” and to a further update in early 2027, and says nothing about rebuilding either way.
The Word That Draws the Line
The update turns on one word: exclusively. In practical terms, the consequence falls on data for which no usable copy remained available outside the affected region or zone. Everything that had been replicated to another region, or backed up outside it, was never in that category. The company’s own account of the last six months reads as a sequence of attempts to move as much as possible out of the first category and into the second. In the first days of March it encouraged customers “to replicate Amazon S3 and critical data from the ME-SOUTH-1 Region to another AWS Region,” pointing them to the United States, Europe or Asia Pacific and to its own guide to S3 replication. By April 30 the advice had hardened to “recover their resources in other Regions from remote backups.” The September note says most customers migrated their workloads before the region became unavailable, and that for the remainder AWS “exhausted every option for restoring data and resources that had not been migrated.”
For a hosting provider that is the whole lesson in one paragraph. A copy in another Availability Zone protects against many failures. It does not protect against the loss of the entire region. That was true before March and it is true of every provider, not only AWS. What the notice adds is a written statement from a hyperscale operator that it cannot restore access to region-only data for some customers.
About the Data
Every statement attributed to AWS comes from the entries for the Middle East (Bahrain) and Middle East (UAE) regions on the AWS Health status page, read in full from its event history, from the first UAE notice on March 1 and the first Bahrain notice on March 2 through the two updates of September 15. The description of how regions and Availability Zones are designed, and the count of zones and regions, come from AWS’s global infrastructure page as it stood on September 17. The cause of the damage is given in AWS’s own words and nothing beyond them. Dates are given in Coordinated Universal Time. The reading of what the notices imply for backup practice is ours.