AWS admits Iran strikes destroyed customer data for good
Six months after Iranian drones hit Amazon's Gulf data centres, AWS has confirmed that some customer data held in Bahrain and the UAE cannot be recovered at all.

Amazon Web Services has told customers that data destroyed when Iranian drones hit its data centres in Bahrain and the United Arab Emirates cannot be recovered. An update to the company's service dashboard on 15 September said AWS was “unable to restore access to the resources and data” held in some of the damaged facilities. Reuters reported the admission first, and it arrives roughly six and a half months after the strikes.
The detail matters more than the headline. In the UAE region, customer data was irretrievably lost in one of three availability zones, the one AWS labels mec1-az2. Each availability zone is served by one or more Amazon data centres, so a single zone going dark takes a slice of a customer's redundancy with it. AWS says it is still working on “recovering regional resources” and restoring what was hosted in the other two UAE zones, replacing affected infrastructure with a further update promised for the coming months.
Bahrain fared worse
In Bahrain the picture is worse still. AWS said it could not restore access to resources and data across all three availability zones in that region. “The damage to our infrastructure spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand,” the update said. Customer billing has been suspended in both regions, and the company has now spent more than half a year trying to return them to normal service.
The strikes began on 1 March, in the opening days of the war that started with US-Israeli attacks on Iran on 28 February. AWS immediately told customers to move workloads to other regions and to restore anything inaccessible from remote backups, and a report in March put customer credits at about $150 million. A second Iranian strike hit Amazon's Bahrain sites on 1 April, disrupting a second availability zone there, and on 24 July the Islamic Revolutionary Guard Corps fired missiles specifically at a remaining Amazon data centre structure in Bahrain, damage confirmed by satellite imagery.
What cloud redundancy is actually built to survive
Availability zones exist to absorb the ordinary disasters of running computers at scale: a fire, a flood, a failed generator bank, a bad firmware push. They are not designed for missiles, and AWS's own wording concedes as much. The lesson for anyone running workloads in the Gulf is the unglamorous one that the company gave in March: a live copy somewhere else, and a backup that is not in the same region, is the only kind of redundancy that survives a strike.
Our opinion
Credit where it is due: AWS has now said in plain language what it previously implied, and it is running this admission through the same public dashboard it uses for network blips. That is not nothing, because the alternative is silence and a support ticket. The uncomfortable part is the arithmetic. Multi-region redundancy has been sold for a decade as the answer to the data centre problem, and here is a case where the answer did not clear the bar, not because the design was sloppy but because the threat model was never war. Any business that kept its only copy of something in the Gulf and assumed a second availability zone counted as a backup has just been handed a very expensive correction.
- AWS says resources and data held in some war-damaged data centres cannot be restored, six months after Iranian drone strikes
- All three availability zones in the Bahrain region lost data access, along with mec1-az2 in the UAE region
- Billing is suspended in both regions, and AWS promises a further update in early 2027